Executive Summary
Between June 2024 and July 2025, the Chinese state-sponsored threat group RedNovember (overlapping with Storm-2077 and formerly tagged as TAG-100) orchestrated a far-reaching cyber-espionage campaign targeting government, defense, and technology organizations globally. Leveraging weaponized perimeter device exploits and open-source tools like Pantegana and Cobalt Strike, the group gained initial access via widely used firewalls and VPNs, including SonicWall, Fortinet, Palo Alto, and Ivanti Connect Secure. Victims included ministries, intergovernmental bodies, US defense contractors, European manufacturers, and space organizations. The campaign’s impact highlights persistent perimeter vulnerabilities and demonstrated operational scale and stealth through commodity tooling and strategic timing near geopolitical events.
This incident underscores the shift toward exploiting edge devices and open-source frameworks for stealth, scalable compromise by advanced actors. The trend signals urgent challenges for organizations relying on perimeter appliances and highlights the need to strengthen monitoring, zero trust segmentation, and compliance-driven security controls across hybrid and multicloud environments.
Why This Matters Now
RedNovember’s activity exemplifies a larger risk to organizations globally: state-sponsored actors now routinely exploit public-facing infrastructure using open-source exploitation kits and C2 frameworks. As edge device vulnerabilities accelerate initial access at scale, urgent attention is required for proactive detection, encryption of internal and external data flows, and zero trust practices to prevent and contain intrusions.
Attack Path Analysis
RedNovember gained initial access by exploiting vulnerabilities in exposed edge devices such as VPNs and firewalls, followed by leveraging valid accounts or misconfigurations for privilege escalation within the target cloud and hybrid environments. The attackers then moved laterally across internal segments to access sensitive systems and workloads, establishing command and control through encrypted channels and open-source backdoors like Pantegana and Cobalt Strike. Data was exfiltrated over permitted egress channels, using covert techniques to avoid detection, with the intent of cyber-espionage rather than destructive impact, although operational disruption risk remained.
Kill Chain Progression
Initial Compromise
Description
Exploitation of known or zero-day vulnerabilities in internet-facing VPNs, firewalls, and edge devices to obtain unauthorized access.
Related CVEs
CVE-2024-24919
CVSS 9.8A vulnerability in Check Point Security Gateways allows remote attackers to bypass authentication and execute arbitrary code.
Affected Products:
Check Point Security Gateway – R80.40, R81, R81.10
Exploit Status:
exploited in the wildCVE-2024-3400
CVSS 10A command injection vulnerability in Palo Alto Networks PAN-OS allows remote attackers to execute arbitrary code.
Affected Products:
Palo Alto Networks PAN-OS – < 10.2.3-h4, < 10.1.8-h4, < 9.1.14-h4
Exploit Status:
exploited in the wildCVE-2023-46805
CVSS 9.8An authentication bypass vulnerability in Ivanti Connect Secure allows remote attackers to access restricted resources.
Affected Products:
Ivanti Connect Secure – 9.x, 10.x
Exploit Status:
exploited in the wildCVE-2024-21887
CVSS 9.8A command injection vulnerability in Ivanti Connect Secure allows remote attackers to execute arbitrary commands.
Affected Products:
Ivanti Connect Secure – 9.x, 10.x
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
External Remote Services
Spearphishing Attachment
Web Protocols
Ingress Tool Transfer
Valid Accounts
Account Discovery
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS v4.0 – Change and Vulnerability Management
Control ID: 6.4.2
NYDFS 23 NYCRR 500 – Access Privileges
Control ID: 500.07
DORA (Digital Operational Resilience Act) – ICT Risk Management Framework
Control ID: Art. 9
CISA Zero Trust Maturity Model 2.0 – Asset Visibility and Network Segmentation
Control ID: Pillar: Devices & Networks
NIS2 Directive – Technical and Organizational Measures
Control ID: Article 21(2)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Chinese state-sponsored RedNovember group directly compromised multiple government ministries, directorates, and security organizations globally using perimeter device exploits and zero trust violations.
Defense/Space
Defense Industrial Base and aerospace organizations face critical espionage threats from RedNovember targeting edge devices, with confirmed US defense contractor compromises requiring enhanced segmentation.
Information Technology/IT
IT sector infrastructure including VPNs, firewalls, and cloud services are primary attack vectors for RedNovember, demanding immediate encrypted traffic and east-west security implementations.
Law Practice/Law Firms
Law firms specifically targeted by RedNovember espionage campaigns require enhanced threat detection, anomaly response capabilities, and multicloud visibility to protect sensitive legal communications.
Sources
- RedNovember Targets Government, Defense, and Technology Organizationshttps://www.recordedfuture.com/research/rednovember-targets-government-defense-and-technology-organizationsVerified
- Chinese Cyberespionage Group RedNovember Targets Global Defense and Government Organizationshttps://nubetia.com/chinese-cyberespionage-group-rednovember-targets-global-defense-and-government-organizations/Verified
- Chinese Hackers RedNovember Target Global Governments Using Pantegana and Cobalt Strikehttps://thehackernews.com/2025/09/chinese-hackers-rednovember-target.htmlVerified
- Chinese Cyberspies Hacked US Defense Contractorshttps://www.securityweek.com/chinese-cyberspies-hacked-us-defense-contractors/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
The attack demonstrates how robust zero trust controls—especially network segmentation, visibility, inline threat prevention, and egress policy enforcement—could have detected and constrained adversary movement across the kill chain, minimizing lateral spread and unauthorized data exfiltration.
Control: Cloud Firewall (ACF)
Mitigation: Block or detect exploitation attempts targeting the exposed perimeter.
Control: Zero Trust Segmentation
Mitigation: Limit lateral privilege escalation through identity-based policy enforcement.
Control: East-West Traffic Security
Mitigation: Detect and restrict suspicious internal communications and pivoting.
Control: Inline IPS (Suricata)
Mitigation: Detect and disrupt known C2 and payload signatures in real-time.
Control: Egress Security & Policy Enforcement
Mitigation: Block or alert on unauthorized outbound data transfers.
Alert security teams to unusual behaviors and accelerate incident response.
Impact at a Glance
Affected Business Functions
- Defense Operations
- Government Communications
- Aerospace Research
- Legal Services
Estimated downtime: 14 days
Estimated loss: $5,000,000
Potential exposure of sensitive government and defense-related information, including classified communications and proprietary aerospace research data.
Recommended Actions
Key Takeaways & Next Steps
- • Deploy zero trust segmentation to prevent lateral attacker movement within cloud and hybrid environments.
- • Enforce cloud-native egress policies to block unauthorized data transfers and command-and-control channels.
- • Implement inline threat detection (IPS), focusing on real-time inspection of inbound, east-west, and outbound traffic.
- • Enhance continuous visibility and centralized policy control for all cloud and on-prem workloads and services.
- • Regularly test and patch perimeter devices and actively monitor for anomalous compromise indicators at the edge.



