Unfading Sea Haze is a China-aligned cyberespionage threat cluster associated with activity tracked as CL-STA-1049. In 2025 it was observed targeting a government organization in Southeast Asia as part of a broader, multi-cluster intrusion set focused on maintaining long-term access to sensitive networks and exfiltrating data. The cluster’s observed activity occurred in April and August 2025. The group is characterized by stealthy post-compromise tradecraft and persistence-focused malware deployment. CL-STA-1049 used a novel loader known as Hypnosis to deploy the FluffyGh0st remote access trojan through DLL sideloading with a legitimate executable, indicating an emphasis on defense evasion and covert execution. FluffyGh0st provides remote control capability and plugin-based functionality consistent with long-term espionage operations. Reporting on the broader campaign also links the cluster to multi-payload strategies and overlapping tactics, techniques, and procedures with other China-aligned operations. High-confidence reporting ties CL-STA-1049 to Unfading Sea Haze and assesses the actor’s objective as persistent access to government networks for continued collection and data theft rather than disruptive or destructive effects. The exact initial access vector used in the observed 2025 activity remains unknown.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
34 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with the broader 2025 campaign targeting a Southeast Asian government, using stealthy methods to preserve access and support data theft objectives.
Stealthy espionage cluster using DLL sideloading and a custom loader to deploy FluffyGh0st RAT for persistent remote access and espionage against a Southeast Asian government target.
China-aligned activity cluster targeting a Southeast Asian government organization using a novel DLL loader and RAT to gain long-term persistent access to sensitive government networks.
Stealth-focused espionage cluster using DLL sideloading and a novel loader to deploy FluffyGh0st RAT for persistent remote access against a Southeast Asian government target.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.