A Chinese state-sponsored threat actor has been identified as the source of a suspected cyber espionage activity cluster that was previously discovered to target international government and commercial sector organizations in Africa, Asia, North America, South America, and Oceania.
After monitoring the activities under the name TAG-100, Recorded Future has now promoted it to the hacker collective RedNovember. Microsoft also tracks it under the name Storm-2077.
The Mastercard-owned company said in a report shared with The Hacker News that RedNovember (which overlaps with Storm-2077) used the Go-based backdoor Pantegana and Cobalt Strike to target perimeter appliances of well-known companies worldwide between June 2024 and July 2025.
The group has broadened the scope of its targeting to include both public and private sector entities read more about Chinese Hackers RedNovember Target Global Governments Using Pantegana and Cobalt Strike.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
