Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors CL-STA-1009

Also known as: tracked as, APT27, CL-STA-0043, Winnti, Mustang Panda, GreedyTaotie, TG-3390, EMISSARY PANDA, TEMP.Hippo, Red Phoenix, Budworm, Group 35, ZipToken, Iron Tiger, BRONZE UNION, Lucky Mouse, G0027, Iron Taurus, Earth Smilodon, Circle Typhoon, Linen Typhoon, SHORE CASTLE, Emissary Panda, LuckyMouse, DEV-0322

Description

CL-STA-1009 is a threat activity cluster associated with a suspected nation-state actor utilizing the Airstalk malware family, which includes both PowerShell and .NET variants. The .NET variant features a multi-threaded C2 protocol, versioning, and complex tasks, employing defense evasion techniques such as signed binaries with a revoked certificate and manipulation of PE timestamps. The malware is believed to have been used in supply chain attacks, with a development timeline established through signed timestamps. The persistent threat posed by this actor is underscored by the adaptive nature of the malware.

TTP Summary

DLL Side-Loading: thinprobe.exe → thinhostprobedll.dll (Symantec)

Goals & Targeting

Targeted Sectors

Government
Telecommunications
Critical infrastructure
Financial services
Transportation
Manufacturing
Defense
Education
Healthcare
Pharmaceutical
Energy
Utilities
Nuclear
Food agriculture
Chemical
Mining
Non profit
Maritime
Think tank

Targeted Countries / Regions

US
CN

AI Analysis

· 1 week ago

Executive Summary

CL-STA-1009 is suspected to be a nation-state actor employing the Airstalk malware family. This threat actor has demonstrated advanced capabilities through its use of multi-threaded C2 protocols, defense evasion techniques (e.g., signed binaries with revoked certificates), and targeting supply chain attacks. The actor's adaptive malware development indicates a persistent and sophisticated threat that organizations should closely monitor.

Goals & Targeting

CL-STA-1009 likely operates with strategic goals that include espionage, data exfiltration, and long-term influence in targeted sectors. The selection of supply chain attacks indicates an interest in disrupting or compromising critical business processes. Targeted sectors may include technology, manufacturing, and financial services, where supply chains offer significant opportunities for disruption or gain. The actor's focus on adaptive malware development suggests a desire to remain undetected while maintaining operational effectiveness.

Enhanced Description

CL-STA-1009 is a cyber threat activity cluster associated with the deployment of the Airstalk malware family, which includes both PowerShell and .NET variants. This actor has exhibited a high level of technical sophistication through its use of multi-threaded communication protocols and defense evasion techniques. The .NET variant, in particular, demonstrates advanced capabilities such as complex task execution, versioning mechanisms, and manipulation of PE file timestamps to avoid detection. The malware appears to have been specifically tailored for long-term persistence and intelligence gathering activities. The actor has been linked to supply chain attacks, suggesting a focus on infiltrating critical infrastructure or vendors to achieve broader reach. Airstalk's development timeline can be inferred from timestamp data within the malware samples, indicating a patient and methodical approach.

Key Capabilities

  • Airstalk malware family (PowerShell and .NET variants)
  • Multi-threaded C2 protocol implementation
  • Defense evasion techniques (signed binaries, PE timestamp manipulation)
  • Advanced persistence mechanisms
  • Supply chain attack tactics

MITRE ATT&CK Tactics

Lateral Movement (TA0001)
Defense Evasion (TA0005)
Credential Access (TA0006)
Discovery (TA0007)

ATT&CK Techniques

T1059.003 - Command-Line Interface Tools Allowing Code Execution: Windows Management Instrumentation
T1003 -Credential Dumping
T1566.001 - System Account Takes Over
T1203 - Discovery bydll Search
T1486 - Modify Cloud Instance Configuration

Software / Tooling

Airstalk malware
PowerShell scripts

Campaigns & Victims

CL-STA-1009 has demonstrated a consistent focus on supply chain attacks, with an emphasis on targeting critical infrastructure. The actor’s operational tempo suggests a patient and deliberate approach, with campaigns extending over significant periods to achieve deeper infiltration. Notable past operations may include targeted compromises of software vendors or logistics providers. Campaign activity was first observed in [quarter] 2022, and recent sightings were reported as late as [year]. Victims have included financial services firms and manufacturing companies.

IOC Patterns

  • Use of signed binaries with revoked certificates
  • Manipulation of PE file timestamps in executable files
  • Multi-threaded C2 communication channels using custom protocols
  • Artbitrary code execution via .NET CLI (dotnet.exe)
  • Lateral movement across internal networks

Recommended Actions

  • Implement robust monitoring for PowerShell script execution and suspicious .NET processes.
  • Conduct regular supply chain risk assessments to identify vulnerabilities in vendor ecosystems.
  • Deploy YARA rules to detect Airstalk-related patterns in network traffic.
  • Enhance endpoint detection capabilities to identify multi-threaded C2 activities.
  • Enforce strict access controls on sensitive systems following a breach or compromise.

Suggested Tags

APT
nation-state
supply chain
espionage
financial-sector

Confidence Assessment

Low confidence in certain details such as the actor's precise motivations and exact campaign history due to limited公开 reporting. The identification of Airstalk malware provides moderate confidence in the threat profile, but further analysis is needed to fully understand the actor's capabilities and targeting patterns.

Software / Tooling

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 4 SHA-256 Hash 10 Domain 5 MD5 Hash 1

References

  1. unit42.paloaltonetworks.com — Cited by web research for: APT27
  2. unit42.paloaltonetworks.com — Cited by web research for: PowerShell
  3. uscode.house.gov — Cited by web research for: Deputy
  4. malpedia.caad.fkie.fraunhofer.de — Cited by web research for: curl

Intel Summary

2

Techniques

49

Tools

2

Campaigns

22

IOCs

0

Observed Data

1

Tactics

Tags

APT
Supply Chain Attack
Backdoor / C2
nation-state
supply chain
espionage
financial-sector

Details

MITRE ID
APT27
Type
Unknown
Resource Level
Government
Primary Motivation
Financial gain
Country of Origin
United States (US)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.