Recorded Future
RedNovember Cyber Threat Analysis Report
Pages
23
Time to read
26 mins
Publication
Language
English
Pages
23
Time to read
26 mins
Publication
Language
English
This report is a cyber threat analysis detailing the activities of RedNovember, a Chinese state-sponsored cyber-espionage group. The document outlines RedNovember's strategic targeting of a diverse range of entities, including government, intergovernmental, and private sector organizations globally. It highlights the group's use of open-source tools and vulnerability exploitation against internet-facing devices, which include firewalls, VPNs, and email servers. The report provides an overview of RedNovember's operational tactics, including the use of command-and-control frameworks such as Pantegana and Cobalt Strike. Additionally, it chronicles the group's activities between June 2024 and July 2025, noting specific instances of targeting, reconnaissance, and compromise of various organizations, including defense contractors and governmental bodies in multiple regions. The analysis emphasizes the broader implications of RedNovember's tactics in the context of state-sponsored cyber activities and the vulnerabilities of critical infrastructure.