logo

RedNovember Targets Government, Defense, and Technology Organizations

ID: b7e16601-c43e-5a3f-98dc-ecb236415c7c

STIX ID: report--b7e16601-c43e-5a3f-98dc-ecb236415c7c

Feed Name: Recorded Future Blog

Threat Score
90/100

Date Published: 2025-09-24

Date Updated: 2026-04-28

...
...

Insikt Group attributes a broad cyber-espionage campaign to a Chinese state-sponsored group named RedNovember (formerly TAG-100), which from mid-2024 to mid-2025 targeted government, defense, aerospace, law firms, and critical private-sector organizations worldwide by exploiting internet-facing/perimeter devices (VPNs, firewalls, OWA, routers) and using open-source and commercial tooling (Pantegana, Cobalt Strike, SparkRAT, LESLIELOADER). The report provides detailed victimology, technical analysis, IoCs (domains, IPs, SHA256s), a LESLIELOADER YARA rule, observed use of publicly released PoC exploits (e.g., for Ivanti, Check Point, Palo Alto), and recommended mitigations for detection and patching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.