RedNovember targets exposed edge devices
Case score 57
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 57
- Main story score
- 57
- Related evidence lift
- +0 / 20
- Contributing updates
- 0
- Context updates
- 0
- Campaign Primary campaign event with the full case value and no additional supporting activity. main
Overview
Latest development Open development history Recorded Future describes RedNovember's PoC-driven espionage Recorded Future described RedNovember, also tracked as Storm-2077, as a Chinese APT that watches vulnerability disclosures and moves quickly when public PoCs appear. The group was tied to probes against Check Point security gateways and Palo Alto GlobalProtect, used tools such as LeslieLoader, SparkRAT, Pantegana, and Cobalt Strike, and was associated with espionage against governments and sensitive-sector organizations across multiple regions.
-
RedNovember recon on Taiwanese strategic infrastructure
On Dec. 9, 2024, RedNovember performed cyber reconnaissance on a location in Taiwan tied to semiconductor research and development and a Taiwanese military airbase. The activity continued for a week after that date, underscoring interest in strategically sensitive infrastructure.
-
Check Point releases CVE-2024-24919 fix
Check Point security gateways were patched on May 28, 2024 after CVE-2024-24919, a high-severity arbitrary file read flaw, was acknowledged by the vendor. The fix followed exploitation of the issue as a zero-day in April and May 2024 and narrowed the immediate window for exposed gateways.