Find notable cyber news and cases, enriched with sources, timelines, and signals.
Campaign

RedNovember targets exposed edge devices

Updated 24.09.2025 19:36
Case score 57
Members 1 First seen 24.09.2025 04:00 Latest activity 24.09.2025 19:36

Overview

**RedNovember**, also tracked as **Storm-2077**, is a suspected Chinese espionage operation focused on internet-facing perimeter appliances. Recorded Future says the group moved quickly after public vulnerability disclosures and used exploit-driven access together with tools such as **LESLIELOADER**, **Pantegana**, and **Cobalt Strike**. The available evidence ties the activity to **CVE-2024-24919** on Check Point gateways and **CVE-2024-3400** on Palo Alto Networks **PAN-OS GlobalProtect**, with victim reporting across multiple regions and sensitive sectors. Patch and hardening guidance for exposed edge devices narrows the window for abuse, but the full scale of compromise remains unknown.
Latest development Open development history 2 earlier developments Recorded Future describes RedNovember's PoC-driven espionage Recorded Future described RedNovember, also tracked as Storm-2077, as a Chinese APT that watches vulnerability disclosures and moves quickly when public PoCs appear. The group was tied to probes against Check Point security gateways and Palo Alto GlobalProtect, used tools such as LeslieLoader, SparkRAT, Pantegana, and Cobalt Strike, and was associated with espionage against governments and sensitive-sector organizations across multiple regions.
  1. Earlier development

    RedNovember recon on Taiwanese strategic infrastructure

    On Dec. 9, 2024, RedNovember performed cyber reconnaissance on a location in Taiwan tied to semiconductor research and development and a Taiwanese military airbase. The activity continued for a week after that date, underscoring interest in strategically sensitive infrastructure.

  2. Earlier development

    Check Point releases CVE-2024-24919 fix

    Check Point security gateways were patched on May 28, 2024 after CVE-2024-24919, a high-severity arbitrary file read flaw, was acknowledged by the vendor. The fix followed exploitation of the issue as a zero-day in April and May 2024 and narrowed the immediate window for exposed gateways.

Signals

Impact signals
CVEs/products
Geographic context
Status
Threat context

Threat actor context

2 listed

Malware & tooling context

4 families · 1 tools
Tools

Technical intelligence

Existing Case data

Member happenings

Campaign RedNovember (Storm-2077) public-PoC espionage campaign
Updated 24.09.2025 04:00 Lead Contribution 57
Objective Espionage Campaign Active

**RedNovember** is a suspected **Chinese state-sponsored** campaign also tracked as **Storm-2077** that targeted **perimeter appliances** of high-profile organizations globally between **June 2024 and July 2025**. Recorded Future says the group used the **Go-based backdoor Pantegana** and **Cobalt Strike** during intrusions, and earlier abuse included **CVE-2024-24919** and **CVE-2024-3400** on exposed security products. The activity expanded across **government** and **private sector** targets, including **defense and aerospace**, **space organizations**, and **law firms**. The campaign matters because it shows a persistent espionage operation that uses public exposure on internet-facing devices to gain access across multiple regions and sectors.