CL-STA-0048 is a China-linked cyber-espionage activity cluster tracked by Palo Alto Networks Unit 42. Active since at least May 2024, it targets high-value organizations in South Asia, particularly telecommunications organizations and government agencies. Its objectives include obtaining government employees’ personal information and stealing sensitive organizational and customer data. The cluster exploits internet-facing applications and services, including Microsoft IIS, Apache Tomcat, and Microsoft SQL Server, and has also exploited SAP NetWeaver Visual Composer vulnerability CVE-2025-31324. Following compromise, it enumerates processes, directories, networks, and application environments using PowerShell and native utilities. Its payload-delivery technique, termed Hex Staging, incrementally writes hexadecimal-encoded payload chunks and decodes them with certutil, reducing reliance on conventional download mechanisms. CL-STA-0048 deploys PlugX, Cobalt Strike, and Winos4.0-based malware. It uses DLL sideloading and process injection, attempts credential theft through LSASS dumping, and employs Potato Suite tools and SspiUacBypass for privilege escalation. Persistence includes creating privileged SQL database accounts. SoftEther VPN, Stowaway, and iox provide tunneling and proxy capabilities through compromised infrastructure. The cluster searches databases for sensitive records, stages collected information, and exfiltrates it through command-and-control channels. A distinctive technique encodes stolen data into DNS subdomains and triggers lookups using ping commands. Its database harvesting includes searches for telephone-related fields and extraction of personal and customer information. Native-tool abuse, encoded staging, in-memory execution, and traffic tunneling support stealthy post-exploitation operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
38 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
40 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a Chinese espionage group previously observed exploiting SAP product vulnerabilities, specifically CVE-2025-31324 affecting SAP products including SAP NetWeaver.
Referenced as a China-nexus espionage cluster previously observed weaponizing SAP product flaws including CVE-2025-31324.
China-linked cluster targeting IIS servers and using hex-encoded DNS subdomain queries for data exfiltration.
China-aligned threat cluster previously observed singling out IIS web servers; noted as tactically close to OP-512.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.