Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Storm-2077

Also known as: TAG-100, RedNovember, overlapping with Storm-2077

Description

Storm-2077 (also known as TAG‑100/RedNovember) has been linked to Chinese state‑sponsored threat activity focused on espionage. The campaign typically begins by targeting internet‑facing network security devices—Citrix NetScaler, F5 BIG‑IP, Palo Alto GlobalProtect, Check Point VPN and others—with exploitation of publicly disclosed CVEs (e.g., CVE‑2022‑30190, CVE‑2024‑3400). Once initial access is achieved, the actors deploy a mix of open‑source backdoors (Pantegana, BRICKSTORM, SparkRAT) and commercial frameworks (Cobalt Strike) to maintain persistence, pivot inside the network, and exfiltrate stolen credentials and enterprise data via cloud storage services such as MEGA. Delivery vectors include spearphishing attachments, malicious Word documents with macros or embedded exploits, typosquatted domains, and anonymous file‑sharing sites used for staging malware. The group’s operations emphasize rapid exploitation of new PoC vulnerabilities and the use of ubiquitous infrastructure tools (PowerShell, Beacon, Matrix) to obfuscate attribution. While many TTPs overlap with other state‑supported APTs (e.g., North Korean or Iranian actors), the consistent targeting of perimeter appliances and public cloud exfiltration strongly points to a focused, high‑budget espionage initiative. Storm-2077’s operational tempo appears cyclical, with intensified activity against aerospace, defense, utilities, and financial sectors during U.S. legislative windows. Recent engagements involved port‑scan reconnaissance against major U.S. aerospace firms and exploitation of Ivanti Connect Secure VPNs in Korea. Overall, the actor’s strategy showcases a blend of low‑barrier vulnerability exploitation and sophisticated command & control to achieve strategic intelligence objectives while minimizing footprints.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Aerospace
Legal services
Education
Telecommunications
Transportation
Critical infrastructure
Non profit
Manufacturing
Nuclear
Utilities
Media
Healthcare
Construction
Aviation
Information technology

Targeted Countries / Regions

US
CN
TW
KR
GB
KP
IR
IL

AI Analysis

Grounded in web research
· analyzed in 4 chunks · 1 day ago

Executive Summary

Storm-2077, operating under the aliases TAG‑100 and RedNovember, is a sophisticated cyber‑espionage actor believed to be state‑sponsored, targeting a broad spectrum of government and critical infrastructure sectors worldwide. The group exploits publicly disclosed vulnerabilities in perimeter appliances and leverages open‑source backdoors such as Pantegana and BRICKSTORM, combined with commercial tools like Cobalt Strike, to gain initial footholds and exfiltrate data to cloud storage services.

Goals & Targeting

The primary objective for Storm-2077 is to gather actionable intelligence from sovereign, defense, and industry stakeholders across multiple geographies. By compromising internet‑facing perimeter appliances that often have rich configuration data and privileged network access, the group can pivot laterally into core asset networks. Once inside, they focus on credential harvesting and exfiltration of both structured documents (e.g., procurement contracts, policy files) and unstructured data (emails, communications). Their sector coverage—government, defense, aerospace, utilities, finance, healthcare and more—suggests a broad intelligence mandate likely aimed at enhancing situational awareness for their sponsoring state in geopolitical, economic, or military arenas.

Enhanced Description

Key Capabilities

  • Deploys open‑source tools such as Pantegana
  • Employs stealthy backdoor malware like BRICKSTORM for persistence and evasion
  • Utilizes SparkRAT and Cobalt Strike for remote access, post‑exploitation, and command-and-control
  • Exploits publicly disclosed vulnerabilities in perimeter appliances (Citrix NetScaler, F5 BIG‑IP, Palo Alto GlobalProtect CVE‑2024‑3400, Check Point VPN CVE‑2024‑24919, Microsoft Office Follina CVE‑2022‑30190)
  • Conducts port scanning and network reconnaissance against targeted organizations
  • Exfiltrates stolen data via cloud storage services (e.g., MEGA)
  • Delivers malicious payloads through compromised or typosquatted domains and anonymous file-sharing sites
  • Uses malicious Word documents with macros or embedded exploits for delivery

MITRE ATT&CK Tactics

Exfiltration
Initial Access
Reconnaissance
Command and Control
Discovery
Execution

ATT&CK Techniques

T1204
T1566.001
T1071
T1071.001
T1190
T1590.006
T1583.003
T1571
T1567.002
T1021
T1046
T1203

Software / Tooling

Pantegana
BRICKSTORM
Cobalt Strike
SparkRAT
Beacon
PowerShell
Matrix

Campaigns & Victims

Storm‑2077 demonstrates a methodical exploitation cycle: reconnaissance via port scanning, exploitation of known perimeter CVEs, deployment of backdoors and commercial C2 frameworks, lateral movement within target networks, and data exfiltration to public cloud services. Victim selection spans high‑value sectors—including defense, aerospace, utilities, finance, healthcare, education, and telecommunications—across the US, China, Taiwan, South Korea, Great Britain, North Korea, Iran, Israel, and other countries. The group’s activity peaks around political or procurement milestones, suggesting a politically motivated intelligence agenda. Notably, in mid‑2024 they were observed targeting U.S. aerospace firms through IP 209.141.46.57 and later shifting focus to South Korean non‑profits and security agencies by early 2025. Operational tempo is moderately frequent: quarterly bursts of reconnaissance and exploitation are followed by silent data exfiltration windows. The use of open‑source backdoors and commercial C2 infrastructure complicates attribution, yet the consistent pattern of targeting perimeter appliances and exploiting zero‑day or low‑severity CVEs indicates a mature, resource‑rich threat actor. The campaign is currently active; however, precise dates for first and last observed activity are not publicly confirmed. The reliance on widely available tools also suggests that the organization can adapt quickly to new vulnerabilities, maintaining an evolving attack surface.

IOC Patterns

  • Domain names pointing to command-and-control or staging sites
  • IP addresses of C2 servers and exploitation endpoints
  • SHA-256 file hashes for known backdoor executables such as Pantegana and SparkRAT
  • URLs containing typosquatted domains used in phishing and malware delivery (e.g., login.offiec.us kg)
  • References to CVE identifiers (e.g., CVE‑2022‑30190, CVE‑2024‑3400)

Recommended Actions

  • Patch and harden internet-facing perimeter devices (Citrix NetScaler, F5 BIG-IP, Palo Alto GlobalProtect, Check Point VPN) to mitigate known CVEs.
  • Apply mitigations for Microsoft Office Follina (CVE‑2022‑30190).
  • Block or closely monitor traffic to/from known C2 domains/IPs associated with Pantegana, SparkRAT, Cobalt Strike and BRICKSTORM.
  • Implement comprehensive logging and monitoring of public-facing applications and VPN tunnels; detect port-scanning and anomalous remote service connections.
  • Segment edge device networks and enforce strict access controls to limit lateral movement from compromised perimeter points.
  • Block or filter typosquatted domains (e.g., login.offiec.us kg) and anonymous file-sharing sites used for staging malware.
  • Deploy IDS/IPS rules for CVE exploitation signatures, non-standard port activity, and known backdoor binaries.
  • Enforce policy against malicious Word documents with macros; employ web filtering to block such content.

Suggested Tags

Storm-2077
TAG-100
RedNovember
Chinese state-sponsored
cyber espionage
high-profile perimeter appliance targeting
data exfiltration cloud storage
use of open-source tools
Cobalt Strike
Follina (CVE‑2022‑30190)
Palo Alto GlobalProtect RCE (CVE‑2024‑3400)
Aerospace & Defense Industry Targeting
Edge Device Vulnerability Exploitation
U.S. Defense Industrial Base
typosquatting
anonymous file sharing

Confidence Assessment

The intelligence on Storm-2077 is derived from multiple independent reports and observable TTPs, giving a moderate‑high confidence in the general attribution model (Chinese state-sponsored espionage) and its core capabilities. However, gaps remain: precise operational timelines are unclear, attribution remains partially ambiguous due to overlapping tool sets with other APT groups, and limited publicly available details on sample counts and incident-specific outcomes reduce the granularity of threat assessment.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

IPv4 Address 7 Domain 4 SHA-256 Hash 8 Filename 1

References

  1. www.recordedfuture.com — Cited by web research for: T1071.001
  2. attack.mitre.org — Cited by web research for: Interception
  3. cloud.google.com — Cited by web research for: systemd
  4. www.microsoft.com — Cited by web research for: Microsoft Teams
  5. apt.etda.or.th — Cited by web research for: Financial Services
  6. https://attack.mitre.org/techniques/T1567/002/ — Cited by AI analysis.

Intel Summary

14

Techniques

40

Tools

0

Campaigns

39

IOCs

0

Observed Data

8

Tactics

Tags

APT
Backdoor / C2
Data Exfiltration
Government Targeting
Storm-2077
TAG-100
RedNovember
Chinese state-sponsored
cyber espionage
high-profile perimeter appliance targeting
data exfiltration cloud storage
use of open-source tools
Cobalt Strike
Follina (CVE‑2022‑30190)
Palo Alto GlobalProtect RCE (CVE‑2024‑3400)
Aerospace & Defense Industry Targeting
Edge Device Vulnerability Exploitation
U.S. Defense Industrial Base
typosquatting
anonymous file sharing

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.