The China-linked advanced persistent threat (APT) group Phantom Taurus has escalated espionage activities targeting government and telecommunications sectors across Africa, the Middle East, and Asia, using a newly identified .NET malware suite named NET-STAR. First observed by Unit 42 in June 2023 cluster CL-STA-0043 and temporarily labeled TGR-STA-0043 (Operation Diplomatic Specter) in May 2024, Phantom Taurus is now recognized as a distinct threat actor. Over the past two and a half years, Phantom Taurus has consistently targeted ministries of foreign affairs, embassies, and organizations tied to geopolitical and military affairs. Phantom Taurus’s targeting pattern aligns with the PRC’s strategic interests by focusing on diplomatic communications, defense intelligence, and critical government operations in regions where China seeks to expand its influence. While many Chinese APTs use tools like China Chopper and the Potato suite, Phantom Taurus stands out with uniquely developed tactics, techniques, and procedures (TTPs) that facilitate highly covert and persistent intrusions. Unit 42’s analysis revealed that Phantom Taurus, a specialized and compartmentalized PRC-linked APT group, shares infrastructure with other Chinese cyber espionage actors but stands out through its exclusive tools and evolved tactics, progressing from vague activity in 2023 to advanced, stealthy database-targeting operations by 2025. Palo Alto Networks customers can protect against these threats using Advanced WildFire, Advanced Threat Prevention, Cortex XDR, and XSIAM. The emergence of NET-STAR signals a notable increase in Chinese APT capabilities targeting internet-facing servers. Organizations running IIS web services in sensitive regions should monitor w3wp.exe memory and unusual ASPX file behavior to detect potential intrusions. Enforce least-privilege SQL account usage and regularly rotate administrative credentials to prevent data theft via scripts like mssq.bat. Deploy Endpoint Detection and Response (EDR) solutions capable of inspecting in-memory .NET activity and detecting AMSI/ETW bypass techniques.
Apache ActiveMQ users are being urged to immediately apply security updates following the disclosure of two significant vulnerabilities that could expose messaging infrastructures ...
Cybersecurity researchers have identified a previously undocumented threat cluster named OP-512, which is actively targeting internet-facing Microsoft Internet Information Services...
Security researchers have uncovered a large-scale cyber campaign in which threat actors combined exploited Fortinet weaknesses, AI-assisted tooling, and custom command-and-control ...