The Containment Era is here. →Explore

Executive Summary

Between June 2024 and July 2025, the Chinese state-sponsored threat group RedNovember (overlapping with Storm-2077 and formerly tagged as TAG-100) orchestrated a far-reaching cyber-espionage campaign targeting government, defense, and technology organizations globally. Leveraging weaponized perimeter device exploits and open-source tools like Pantegana and Cobalt Strike, the group gained initial access via widely used firewalls and VPNs, including SonicWall, Fortinet, Palo Alto, and Ivanti Connect Secure. Victims included ministries, intergovernmental bodies, US defense contractors, European manufacturers, and space organizations. The campaign’s impact highlights persistent perimeter vulnerabilities and demonstrated operational scale and stealth through commodity tooling and strategic timing near geopolitical events.

This incident underscores the shift toward exploiting edge devices and open-source frameworks for stealth, scalable compromise by advanced actors. The trend signals urgent challenges for organizations relying on perimeter appliances and highlights the need to strengthen monitoring, zero trust segmentation, and compliance-driven security controls across hybrid and multicloud environments.

Why This Matters Now

RedNovember’s activity exemplifies a larger risk to organizations globally: state-sponsored actors now routinely exploit public-facing infrastructure using open-source exploitation kits and C2 frameworks. As edge device vulnerabilities accelerate initial access at scale, urgent attention is required for proactive detection, encryption of internal and external data flows, and zero trust practices to prevent and contain intrusions.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The attack highlighted weak points in encrypted traffic, east-west visibility, and segmentation controls, many regulated under HIPAA, PCI, and NIST frameworks.

Cloud Native Security Fabric Mitigations and ControlsCNSF

The attack demonstrates how robust zero trust controls—especially network segmentation, visibility, inline threat prevention, and egress policy enforcement—could have detected and constrained adversary movement across the kill chain, minimizing lateral spread and unauthorized data exfiltration.

Initial Compromise

Control: Cloud Firewall (ACF)

Mitigation: Block or detect exploitation attempts targeting the exposed perimeter.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Limit lateral privilege escalation through identity-based policy enforcement.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Detect and restrict suspicious internal communications and pivoting.

Command & Control

Control: Inline IPS (Suricata)

Mitigation: Detect and disrupt known C2 and payload signatures in real-time.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Block or alert on unauthorized outbound data transfers.

Impact (Mitigations)

Alert security teams to unusual behaviors and accelerate incident response.

Impact at a Glance

Affected Business Functions

  • Defense Operations
  • Government Communications
  • Aerospace Research
  • Legal Services
Operational Disruption

Estimated downtime: 14 days

Financial Impact

Estimated loss: $5,000,000

Data Exposure

Potential exposure of sensitive government and defense-related information, including classified communications and proprietary aerospace research data.

Recommended Actions

  • Deploy zero trust segmentation to prevent lateral attacker movement within cloud and hybrid environments.
  • Enforce cloud-native egress policies to block unauthorized data transfers and command-and-control channels.
  • Implement inline threat detection (IPS), focusing on real-time inspection of inbound, east-west, and outbound traffic.
  • Enhance continuous visibility and centralized policy control for all cloud and on-prem workloads and services.
  • Regularly test and patch perimeter devices and actively monitor for anomalous compromise indicators at the edge.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image