Also known as: TAG-100, RedNovember, overlapping with Storm-2077
Storm-2077 (also known as TAG‑100/RedNovember) has been linked to Chinese state‑sponsored threat activity focused on espionage. The campaign typically begins by targeting internet‑facing network security devices—Citrix NetScaler, F5 BIG‑IP, Palo Alto GlobalProtect, Check Point VPN and others—with exploitation of publicly disclosed CVEs (e.g., CVE‑2022‑30190, CVE‑2024‑3400). Once initial access is achieved, the actors deploy a mix of open‑source backdoors (Pantegana, BRICKSTORM, SparkRAT) and commercial frameworks (Cobalt Strike) to maintain persistence, pivot inside the network, and exfiltrate stolen credentials and enterprise data via cloud storage services such as MEGA. Delivery vectors include spearphishing attachments, malicious Word documents with macros or embedded exploits, typosquatted domains, and anonymous file‑sharing sites used for staging malware. The group’s operations emphasize rapid exploitation of new PoC vulnerabilities and the use of ubiquitous infrastructure tools (PowerShell, Beacon, Matrix) to obfuscate attribution. While many TTPs overlap with other state‑supported APTs (e.g., North Korean or Iranian actors), the consistent targeting of perimeter appliances and public cloud exfiltration strongly points to a focused, high‑budget espionage initiative. Storm-2077’s operational tempo appears cyclical, with intensified activity against aerospace, defense, utilities, and financial sectors during U.S. legislative windows. Recent engagements involved port‑scan reconnaissance against major U.S. aerospace firms and exploitation of Ivanti Connect Secure VPNs in Korea. Overall, the actor’s strategy showcases a blend of low‑barrier vulnerability exploitation and sophisticated command & control to achieve strategic intelligence objectives while minimizing footprints.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Storm-2077, operating under the aliases TAG‑100 and RedNovember, is a sophisticated cyber‑espionage actor believed to be state‑sponsored, targeting a broad spectrum of government and critical infrastructure sectors worldwide. The group exploits publicly disclosed vulnerabilities in perimeter appliances and leverages open‑source backdoors such as Pantegana and BRICKSTORM, combined with commercial tools like Cobalt Strike, to gain initial footholds and exfiltrate data to cloud storage services.
Goals & Targeting
The primary objective for Storm-2077 is to gather actionable intelligence from sovereign, defense, and industry stakeholders across multiple geographies. By compromising internet‑facing perimeter appliances that often have rich configuration data and privileged network access, the group can pivot laterally into core asset networks. Once inside, they focus on credential harvesting and exfiltration of both structured documents (e.g., procurement contracts, policy files) and unstructured data (emails, communications). Their sector coverage—government, defense, aerospace, utilities, finance, healthcare and more—suggests a broad intelligence mandate likely aimed at enhancing situational awareness for their sponsoring state in geopolitical, economic, or military arenas.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Storm‑2077 demonstrates a methodical exploitation cycle: reconnaissance via port scanning, exploitation of known perimeter CVEs, deployment of backdoors and commercial C2 frameworks, lateral movement within target networks, and data exfiltration to public cloud services. Victim selection spans high‑value sectors—including defense, aerospace, utilities, finance, healthcare, education, and telecommunications—across the US, China, Taiwan, South Korea, Great Britain, North Korea, Iran, Israel, and other countries. The group’s activity peaks around political or procurement milestones, suggesting a politically motivated intelligence agenda. Notably, in mid‑2024 they were observed targeting U.S. aerospace firms through IP 209.141.46.57 and later shifting focus to South Korean non‑profits and security agencies by early 2025. Operational tempo is moderately frequent: quarterly bursts of reconnaissance and exploitation are followed by silent data exfiltration windows. The use of open‑source backdoors and commercial C2 infrastructure complicates attribution, yet the consistent pattern of targeting perimeter appliances and exploiting zero‑day or low‑severity CVEs indicates a mature, resource‑rich threat actor. The campaign is currently active; however, precise dates for first and last observed activity are not publicly confirmed. The reliance on widely available tools also suggests that the organization can adapt quickly to new vulnerabilities, maintaining an evolving attack surface.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The intelligence on Storm-2077 is derived from multiple independent reports and observable TTPs, giving a moderate‑high confidence in the general attribution model (Chinese state-sponsored espionage) and its core capabilities. However, gaps remain: precise operational timelines are unclear, attribution remains partially ambiguous due to overlapping tool sets with other APT groups, and limited publicly available details on sample counts and incident-specific outcomes reduce the granularity of threat assessment.
No campaigns linked yet.
No observed data linked yet.
14
Techniques
40
Tools
0
Campaigns
39
IOCs
0
Observed Data
8
Tactics