Also known as: CL STA 0048, Mustang Panda, tracked as, STAC6451 was published, BRONZE PRESIDENT, TA416, RedDelta, Earth Preta, Smoke Sandstorm, defense companies, APT33, APT28, Fancy Bear, UNC1549
CL-STA-0048 is an advanced threat actor believed to be backed by the Chinese government and identified in several reports under aliases such as Mustang Panda, RedDelta, Earth Preta, and STAC6451. The group focuses on strategic sectors – telecommunications, defense, finance, aerospace, and critical infrastructure – primarily within South Asia but also across a broad geographic footprint including China, India, Brazil, UAE, the US, Taiwan, Iran, North Korea, Ukraine, Pakistan, Vietnam, Romania, Netherlands and Italy. Operationally, CL‑STA‑0048 exploits CVEs in widely used public-facing applications (IIS, Apache Tomcat, MSSQL) to establish footholds. It employs a Hex Staging technique to chunk payloads into obfuscated binaries delivered through Living‑off-the-Land binaries such as cmd.exe and wscript.exe. Once inside the network the actor deploys modular backdoors – ToneShell, ShadowPad, BRICKSTORM – and leverages PlugX or Cobalt Strike for lateral movement and data exfiltration. Command-and-control communication is routed via known malicious domains (sentinelones.com) and IP addresses such as 43.247.135.53, and the actor has been observed using valid code‑signing certificates and DLL side‑loading to evade detection. In addition to traditional credential harvest techniques, the group uses LLM-based automation for generating C2 instructions – a capability previously seen in Russian APT28 malware. This automated workflow reduces manual operator involvement and facilitates rapid, scalable threat dissemination. Defenders should maintain strict patch management on public servers, enable application whitelisting, implement file‑integrity monitoring for staged payloads, enforce code‑signature validation, and observe outbound traffic to known malicious IPs and domains. Detecting activity such as scheduled tasks, unusual PowerShell usage, and DNS beaconing via ping commands can surface early intrusion indicators. The actor remains highly adaptive; it is believed to transition quickly between different toolchains and C2 infrastructure, making continuous monitoring essential.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
CL-STA-0048 is a Chinese state-sponsored APT that targets high‑value telecommunications, government and critical infrastructure across South Asia and the Middle East, primarily for espionage. The group leverages public‑facing vulnerabilities (IIS, Apache Tomcat, MSSQL), delivers obfuscated staged payloads via LOLBins, and uses PlugX and Cobalt Strike to maintain persistence and exfiltrate data. Defenders should prioritize patching exposed services, monitoring for C2 traffic to sentinelones.com and 43.247.135.53, and deploying behavioral detection for LLM‑based command generation.
Goals & Targeting
CL-STA-0048’s strategic objective is primarily espionage of politically or economically significant infrastructure. By compromising telecommunications backbones, governmental networks and critical industrial control systems in South Asia and the Middle East, the group seeks to exfiltrate sensitive information, disrupt communications, and potentially gain a technical advantage for future state-level operations. Target selection focuses on high‑value entities that provide access to large volumes of data – from subscriber databases to operational technology logs. The geographic spread suggests an intent to create multiple footholds across politically relevant regions, facilitating reconnaissance, data theft and possible sabotage should geopolitical tensions arise.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
CL-STA-0048 operates with a high operational tempo, targeting government and telecommunications organizations across South Asia and the broader region. The actor demonstrates consistent use of both exploitation and living‑off-the-land techniques, suggesting a hybrid approach that blends supply‑chain attacks with opportunistic vulnerability exploitation. Past operations include documented SAP NetWeaver intrusions and a CVE-2025-31324 exploit seen in May 2025. The group’s pattern shows a preference for distributed C2 architectures utilizing legitimate domains (sentinelones.com) or IP addresses, combined with sophisticated evasion such as DLL side‑loading, code signing abuse and obfuscated communications. Notable campaigns hint at collaboration or shared infrastructure with other Chinese state sponsors such as Earth Lamia or Stately Taurus, although clear attribution remains incomplete. Their use of LLM‑enhanced C2 instruction generation hints at a shift toward automation, potentially increasing campaign speed and reducing human oversight.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the attribution to a Chinese state-supported actor is moderate, based on recurring patterns, shared toolchains and consistent sector focus. However, gaps remain: the exact timeline of operation initiation, full scope of infrastructure (C2 domains, IP ranges), and precise relationship with other groups such as Earth Lamia or Stately Taurus are not fully established. The reliance on LLMs for C2 instructions is a recent development, and further evidence is needed to confirm whether this capability is unique or shared among multiple APT families.
No campaigns linked yet.
No observed data linked yet.
43
Techniques
47
Tools
0
Campaigns
40
IOCs
0
Observed Data
13
Tactics