Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors CL-STA-0048

Also known as: CL STA 0048, Mustang Panda, tracked as, STAC6451 was published, BRONZE PRESIDENT, TA416, RedDelta, Earth Preta, Smoke Sandstorm, defense companies, APT33, APT28, Fancy Bear, UNC1549

Description

CL-STA-0048 is an advanced threat actor believed to be backed by the Chinese government and identified in several reports under aliases such as Mustang Panda, RedDelta, Earth Preta, and STAC6451. The group focuses on strategic sectors – telecommunications, defense, finance, aerospace, and critical infrastructure – primarily within South Asia but also across a broad geographic footprint including China, India, Brazil, UAE, the US, Taiwan, Iran, North Korea, Ukraine, Pakistan, Vietnam, Romania, Netherlands and Italy. Operationally, CL‑STA‑0048 exploits CVEs in widely used public-facing applications (IIS, Apache Tomcat, MSSQL) to establish footholds. It employs a Hex Staging technique to chunk payloads into obfuscated binaries delivered through Living‑off-the-Land binaries such as cmd.exe and wscript.exe. Once inside the network the actor deploys modular backdoors – ToneShell, ShadowPad, BRICKSTORM – and leverages PlugX or Cobalt Strike for lateral movement and data exfiltration. Command-and-control communication is routed via known malicious domains (sentinelones.com) and IP addresses such as 43.247.135.53, and the actor has been observed using valid code‑signing certificates and DLL side‑loading to evade detection. In addition to traditional credential harvest techniques, the group uses LLM-based automation for generating C2 instructions – a capability previously seen in Russian APT28 malware. This automated workflow reduces manual operator involvement and facilitates rapid, scalable threat dissemination. Defenders should maintain strict patch management on public servers, enable application whitelisting, implement file‑integrity monitoring for staged payloads, enforce code‑signature validation, and observe outbound traffic to known malicious IPs and domains. Detecting activity such as scheduled tasks, unusual PowerShell usage, and DNS beaconing via ping commands can surface early intrusion indicators. The actor remains highly adaptive; it is believed to transition quickly between different toolchains and C2 infrastructure, making continuous monitoring essential.

Goals & Targeting

Targeted Sectors

Government
Telecommunications
Financial services
Defense
Information technology
Critical infrastructure
Aerospace
Education
Transportation
Retail
Healthcare
Manufacturing
Media
Maritime

Targeted Countries / Regions

CN
IN
BR
AE
US
TW
IR
KP
UA
PK
VN
RO
NL
IT

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 4 hours ago

Executive Summary

CL-STA-0048 is a Chinese state-sponsored APT that targets high‑value telecommunications, government and critical infrastructure across South Asia and the Middle East, primarily for espionage. The group leverages public‑facing vulnerabilities (IIS, Apache Tomcat, MSSQL), delivers obfuscated staged payloads via LOLBins, and uses PlugX and Cobalt Strike to maintain persistence and exfiltrate data. Defenders should prioritize patching exposed services, monitoring for C2 traffic to sentinelones.com and 43.247.135.53, and deploying behavioral detection for LLM‑based command generation.

Goals & Targeting

CL-STA-0048’s strategic objective is primarily espionage of politically or economically significant infrastructure. By compromising telecommunications backbones, governmental networks and critical industrial control systems in South Asia and the Middle East, the group seeks to exfiltrate sensitive information, disrupt communications, and potentially gain a technical advantage for future state-level operations. Target selection focuses on high‑value entities that provide access to large volumes of data – from subscriber databases to operational technology logs. The geographic spread suggests an intent to create multiple footholds across politically relevant regions, facilitating reconnaissance, data theft and possible sabotage should geopolitical tensions arise.

Enhanced Description

Key Capabilities

  • Exploitation of public-facing servers such as IIS, Apache Tomcat, and MSSQL
  • Hex Staging payload delivery in obfuscated chunks

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Discovery
Credential Access
Lateral Movement
Collection
Exfiltration
Command and Control

ATT&CK Techniques

T1027
T1053.005
T1068
T1078
T1087
T1132.001
T1105
T1202
T1190
T1574.001
T1189
T1049
T1036.005

Software / Tooling

PlugX
Cobalt Strike
ToneShell backdoor
ShadowPad backdoor
BRICKSTORM malware
NET‑STAR malware
LOLBins (cmd.exe, wscript.exe)

Campaigns & Victims

CL-STA-0048 operates with a high operational tempo, targeting government and telecommunications organizations across South Asia and the broader region. The actor demonstrates consistent use of both exploitation and living‑off-the-land techniques, suggesting a hybrid approach that blends supply‑chain attacks with opportunistic vulnerability exploitation. Past operations include documented SAP NetWeaver intrusions and a CVE-2025-31324 exploit seen in May 2025. The group’s pattern shows a preference for distributed C2 architectures utilizing legitimate domains (sentinelones.com) or IP addresses, combined with sophisticated evasion such as DLL side‑loading, code signing abuse and obfuscated communications. Notable campaigns hint at collaboration or shared infrastructure with other Chinese state sponsors such as Earth Lamia or Stately Taurus, although clear attribution remains incomplete. Their use of LLM‑enhanced C2 instruction generation hints at a shift toward automation, potentially increasing campaign speed and reducing human oversight.

IOC Patterns

  • Vulnerability exploitation (IIS, Apache Tomcat, MSSQL)
  • Obfuscated files or information (Hex Staging)
  • Staged payload delivery via LOLBins
  • Use of common OS binaries for persistence
  • Code‑signing certificate misuse
  • Specific malicious domain sentinelones.com
  • Malicious IP 43.247.135.53 and associates
  • File names cmd.exe, wscript.exe, net.exe, log.dll

Recommended Actions

  • Patch and harden public-facing IIS, Apache Tomcat, and MSSQL servers

Suggested Tags

APT
Espionage
South Asia Targeting
Telecommunications Sector
China‑Nexus Nation State Actor
High-Value Targets
Nation-State Advanced Persistent Threat
Data Theft
Chinese state-sponsored
Cobalt Strike
Backdoor
Privilege Escalation
Code Signing Abuse
Web Application Exploit
Phishing via Job Recruitment
ShadowPad
BRICKSTORM
ToneShell
CVE‑2025‑31324
APT28
Fancy Bear
LLM-based command and control
Automated malware

Confidence Assessment

Confidence in the attribution to a Chinese state-supported actor is moderate, based on recurring patterns, shared toolchains and consistent sector focus. However, gaps remain: the exact timeline of operation initiation, full scope of infrastructure (C2 domains, IP ranges), and precise relationship with other groups such as Earth Lamia or Stately Taurus are not fully established. The reliance on LLMs for C2 instructions is a recent development, and further evidence is needed to confirm whether this capability is unique or shared among multiple APT families.

ATT&CK Techniques

Collection
1 technique
Lateral Movement
1 technique
Privilege Escalation
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. unit42.paloaltonetworks.com — Cited by web research for: Mustang Panda
  2. www.trendmicro.com — Cited by web research for: STAC6451 was published
  3. www.paloaltonetworks.com — Cited by web research for: Smoke Sandstorm
  4. unit42.paloaltonetworks.com — Cited by web research for: T1027
  5. www.recordedfuture.com — Cited by web research for: GolangGhost
  6. https://blog.netmanageit.com/cl-sta-0048-an-espionage-operation-a — Cited by AI analysis.

Intel Summary

43

Techniques

47

Tools

0

Campaigns

40

IOCs

0

Observed Data

13

Tactics

Tags

APT
Backdoor / C2
Government Targeting
State-sponsored
Espionage
South Asia
Telecommunications
Government
South Asia Targeting
Telecommunications Sector
China‑Nexus Nation State Actor
High-Value Targets
Nation-State Advanced Persistent Threat
Data Theft
Chinese state-sponsored
Cobalt Strike
Backdoor
Privilege Escalation
Code Signing Abuse
Web Application Exploit
Phishing via Job Recruitment
ShadowPad
BRICKSTORM
ToneShell
CVE‑2025‑31324
APT28
Fancy Bear
LLM-based command and control
Automated malware

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.