Researchers tied multiple government-focused espionage campaigns to a shared malware development and logistics ecosystem built around CMSTAR and related tooling. FireEye’s analysis of 11 APT campaigns found common malware families, overlapping command-and-control infrastructure, reused code-signing certificates, clustered compile times, and distinctive NSIS manifest artifacts, leading to its assessment that a centralized “Sunshop Digital Quartermaster” supplied malware and operational support to otherwise separate intrusion groups. The report linked 110 malware binaries and 54 domains across campaigns that used families such as Trojan.APT.9002, PoisonIvy, and Gh0st, and described a Chinese-language 9002 Builder that further suggested centralized tooling rather than fully independent operators.
Palo Alto Networks later documented how that model appeared in real-world government targeting. In Mongolia, spear-phishing attacks used politically themed Word documents exploiting CVE-2012-0158 and later CVE-2014-1761 to deploy the Cmstar loader and BBSRAT, with some lures sent from compromised or likely compromised government-associated email accounts and one sample aimed at nearly 2,000 recipients. A separate campaign against Belarusian government entities used Zapad-2017-themed phishing emails, malicious RTF and macro-enabled Word files exploiting CVE-2015-1641, and a disguised SCR file to deliver updated CMSTAR variants alongside newly identified backdoors PYLOT and BYEBY. Across both cases, researchers highlighted shared infrastructure, malware lineage, and tooling overlaps that support the view that multiple espionage operators were drawing from a common malware supply chain.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
12 events from the most recent confirmed update back to the earliest known activity.
Unit 42 observed 20 phishing emails sent between June and August targeting Belarusian government entities, especially defense, foreign affairs, border, and internal affairs organizations. The campaign used updated CMSTAR variants delivered via RTF exploits, macro-enabled Word documents, and a disguised SCR file.
Unit 42 analyzed a campaign targeting multiple Mongolian government offices from August 2015 through February 2016 using weaponized Word documents, Cmstar, and BBSRAT. Later samples added CVE-2014-1761 alongside CVE-2012-0158, and the report linked the tooling to a possible shared 'Digital Quartermaster.'
A phishing email from davaa_ayush@yahoo.com targeted davaa_ayush@mod.gov.mn, suggesting the victim's personal email account may also have been compromised. Palo Alto highlighted this as evidence of attacker access beyond official government accounts.
A phishing email from bilguun@masm.gov.mn used a Dalai Lama-themed lure and targeted nearly 2,000 recipients within the Mongolian government. The scale of the mailing showed broad targeting within government networks.
A phishing email from ganbat_g@bpo.gov.mn targeted a Mongolian government recipient using a lure about the Beijing military parade. The message was part of the broader spear-phishing campaign against Mongolian government offices.
A phishing email sent from altangadas@energy.gov.mn targeted multiple Mongolian government officials with a document themed around Victory Day. Palo Alto cited this as one of the earliest specifically dated emails in the campaign.
In a May 2015 report, Unit 42 analyzed the Cmstar downloader used in spear-phishing attacks exploiting CVE-2012-0158 and linked it to the Lurid/Enfal malware ecosystem. The researchers cited shared infrastructure, recurring "cgl-bin" C2 URL patterns, and overlapping domain-registration details including use of WANGMINGHUA6@GMAIL[.]COM.
The Palo Alto report notes that BBSRAT had previously been associated with ESET's Roaming Tiger campaign. This establishes earlier public reporting connecting the malware family to espionage activity.
FireEye found that 28 Trojan.APT.9002 binaries using the Sunshop PE resource shared the same compile time. The repeated timestamp was December 19, 2012 at 20:25, supporting the assessment of centralized malware packaging or development.
FireEye identified five Trojan.APT.9002 binaries compiled on 2012-07-21 that used the DTL resource and communicated with domains including engage.intelfox[.]com, ru.pad62[.]com, and tank.hja63[.]com. The samples were linked to a Chinese-language GUI tool dubbed '9002 Builder.'
FireEye reported that 11 apparently separate APT campaigns were active during this period and shared development artifacts, malware, and infrastructure. The activity was observed between July 2011 and September 2013 and later formed the basis for FireEye's 'Sunshop Digital Quartermaster' assessment.
In analyzing the Belarus-targeting CMSTAR activity, researchers found two previously unknown payloads named PYLOT and BYEBY delivered from CMSTAR-related infrastructure. PYLOT used RC4-encrypted HTTP communications, while BYEBY operated as a DLL backdoor over TLS on port 443 and could register itself as the VideoSrv service.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
researchcenter.paloaltonetworks.com
Open sourceresearchcenter.paloaltonetworks.com
Open sourceresearchcenter.paloaltonetworks.com
Open sourceblog.paloaltonetworks.com
Open sourcefireeye.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.