InsighthubNews
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
Reading: China’s hacker red noveler target global government using pantegana and cobalt strike
Share
Font ResizerAa
InsighthubNewsInsighthubNews
Search
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
© 2024 All Rights Reserved | Powered by Insighthub News
InsighthubNews > Technology > China’s hacker red noveler target global government using pantegana and cobalt strike
Technology

China’s hacker red noveler target global government using pantegana and cobalt strike

September 24, 2025 4 Min Read
Share

The suspected cyberespionage cluster, previously discovered to target global government and private sector organizations across Africa, Asia, North America, South America and Oceania, is rated as a state-sponsored threat actor.

Recorded Future, who tracked activities under the Moniker Tag-100, has graduated from a hacking group. Rednovember. It is also tracked by Microsoft as Storm-2077.

“Between June 2024 and June 2025, Rednovember (which overlaps with Storm-2077) targeted targeting target appliances from high-profile organizations around the world, using GO-based backdoor pantegana and cobalt strikes as part of the invasion.”

“The group expanded target authority across government and private sector organizations, including defense and aerospace organizations, space organizations, and law firms.”

Some of the new victims of threat leaders include the Central Asian Ministry of Foreign Affairs, the African National Security Agency, the European Government Bureau, and the Southeast Asian government. The group is also believed to have violated at least two US (US) defense contractors, European engine manufacturers, and intergovernmental cooperation agencies focusing on trade in Southeast Asia.

Rednovember, first documented by Future, recorded more than a year ago, detailed the post-Pantegana post-explosion framework and use of sparkrats following the weaponization of known security flaws in several internet-facing boundary appliances from Checkpoint (CVE-2024-24919), Cisco, Citrix, F5, Ivanti and Palo Altolksoves. (CVE-2024-3400), and initial access to SonicWall.

The focus on targeting security solutions such as VPNs, firewalls, load balancers, virtualization infrastructure, and email servers reflects the trends that other China-sponsored hacking groups have entered networks of interest and are increasingly being adopted to maintain long-term sustainability.

A notable aspect of the commerciality of threat actors is the use of pantegana and sparkrats, both open source tools. Recruitment is an attempt to reuse existing programs for their interests and disrupt the attribution efforts that are characteristic of spyers.

See also  Shai-Hulud v2 campaign spreads from npm to Maven, exposing thousands of secrets

The attack uses a publicly available variant of the Go-based loader, Leslieloader, to fire a Spark Rat or Cobalt Strike beacon on the compromised device.

Rednovember is said to use VPN services such as ExpressVPN and Warp VPN to use internet-facing devices, and manage and connect to two servers that communicate with Pantegana, Spark Rat and Cobalt Strike.

Between June 2024 and May 2025, many of the hacking group’s targeting efforts focused on Panama, the US, Taiwan and South Korea. In April 2025, it has been recently found to target safe appliances associated with US-based newspapers and engineering and military contractors.

Recorded Future also said it had identified enemies that likely targeted the Microsoft Outlook Web Access (OWA) portal belonging to a South American country before it visited China.

“Rednovember has historically targeted a diverse range of countries and sectors, suggesting a wide range of intelligence requirements,” the company said. “Rednovender’s activities so far have focused primarily on several key regions, including the US, Southeast Asia, the Pacific region and South America.”

Share This Article
Twitter Copy Link
Previous Article Bladesong is a combat-less yet charming sword game with new demos Bladesong is a combat-less yet charming sword game with new demos
Next Article Charlie Kirk preached, "Love your enemy," but Trump hates him. Charlie Kirk preached, “Love your enemy,” but Trump hates him.

You Might Also Like

MacSync macOS Stealer
Technology

New MacSync macOS stealer uses signed apps to bypass Apple gatekeeper

3 Min Read
Six browser-based attack security teams need to prepare now
Technology

Six browser-based attack security teams need to prepare now

13 Min Read
Two new Super Micro BMC bugs allow malicious firmware to circumvent the trust security route
Technology

Two new Super Micro BMC bugs allow malicious firmware to circumvent the trust security route

4 Min Read
Experts report a surge in automated botnet attacks targeting PHP servers and IoT devices
Technology

Experts report a surge in automated botnet attacks targeting PHP servers and IoT devices

5 Min Read
InsighthubNews
InsighthubNews

Welcome to InsighthubNews, your reliable source for the latest updates and in-depth insights from around the globe. We are dedicated to bringing you up-to-the-minute news and analysis on the most pressing issues and developments shaping the world today.

  • Home
  • Celebrity
  • Environment
  • Business
  • Crypto
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
  • World News
  • Politics
  • Technology
  • Sports
  • Gaming
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service

© 2024 All Rights Reserved | Powered by Insighthub News

Welcome Back!

Sign in to your account

Lost your password?