CL-STA-0043CL-STA-0043

Also known as: CL-STA-0043 · Phantom Taurus · TGR-STA-0043

Known aliases
3

Profile

CL-STA-0043 is a Chinese state-nexus cyber-espionage actor tracked by Palo Alto Networks Unit 42, which promoted the activity cluster to the named threat actor Phantom Taurus in September 2025, having previously designated it TGR-STA-0043 and linked it to the Operation Diplomatic Specter campaign. The group targets government and telecommunications organizations, including ministries of foreign affairs, embassies and diplomatic missions, across Africa, the Middle East and Asia, with a focus on geopolitical and military intelligence collection. It typically gains access by exploiting internet-facing Internet Information Services (IIS) and Microsoft Exchange servers, then performs reconnaissance and privilege escalation using native Windows tooling. In more recent operations the actor deployed NET-STAR, a fileless .NET malware suite targeting IIS web servers that comprises the IIServerCore backdoor and the AssemblyExecuter V1 and V2 loaders.

Aliases· 3

CL-STA-0043Phantom TaurusTGR-STA-0043

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
CL-STA-0048
Actor
TA453
Actor
STAC5143
Actor
Storm-1133
Actor
TA4903
Actor
APT43
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.