CN

Storm-2077Storm-2077

Also known as: TAG-100 · RedNovember · Storm-2077

Origin
CN
Known aliases
3

Profile

TAG-100 is a cyber-espionage APT that targets government and private sector organizations globally, exploiting vulnerabilities in internet-facing devices such as Citrix NetScaler and F5 BIG-IP for initial access. The group employs open-source tools like Pantegana and SparkRAT for persistence and post-exploitation activities, including credential theft and email data exfiltration. TAG-100 has compromised entities in at least ten countries, including two Asia-Pacific intergovernmental organizations, and focuses on sectors like education, finance, and local government. Their operations highlight the challenges of attribution due to the use of off-the-shelf tools and techniques that overlap with other state-sponsored groups.

Aliases· 3

TAG-100RedNovemberStorm-2077

References

  1. https://www.microsoft.com/en-us/security/blog/2024/11/22/microsoft-shares-latest-intelligence-on-north-korean-and-chinese-threat-actors-at-cyberwarcon/
  2. https://www.recordedfuture.com/research/tag-100-uses-open-source-tools-in-suspected-global-espionage-campaign
  3. https://thehackernews.com/2025/09/chinese-hackers-rednovember-target.html

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
TA577
Actor
Storm-0473
Actor
APT27
Actor
Storm-0558
Actor
Storm-1977
Actor
CL-STA-1087
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.