Also known as: tracked as, APT27, CL-STA-0043, Winnti, Mustang Panda, GreedyTaotie, TG-3390, EMISSARY PANDA, TEMP.Hippo, Red Phoenix, Budworm, Group 35, ZipToken, Iron Tiger, BRONZE UNION, Lucky Mouse, G0027, Iron Taurus, Earth Smilodon, Circle Typhoon, Linen Typhoon, SHORE CASTLE, Emissary Panda, LuckyMouse, DEV-0322
CL-STA-1009 is a threat activity cluster associated with a suspected nation-state actor utilizing the Airstalk malware family, which includes both PowerShell and .NET variants. The .NET variant features a multi-threaded C2 protocol, versioning, and complex tasks, employing defense evasion techniques such as signed binaries with a revoked certificate and manipulation of PE timestamps. The malware is believed to have been used in supply chain attacks, with a development timeline established through signed timestamps. The persistent threat posed by this actor is underscored by the adaptive nature of the malware.
DLL Side-Loading: thinprobe.exe → thinhostprobedll.dll (Symantec)
Targeted Sectors
Targeted Countries / Regions
Executive Summary
CL-STA-1009 is suspected to be a nation-state actor employing the Airstalk malware family. This threat actor has demonstrated advanced capabilities through its use of multi-threaded C2 protocols, defense evasion techniques (e.g., signed binaries with revoked certificates), and targeting supply chain attacks. The actor's adaptive malware development indicates a persistent and sophisticated threat that organizations should closely monitor.
Goals & Targeting
CL-STA-1009 likely operates with strategic goals that include espionage, data exfiltration, and long-term influence in targeted sectors. The selection of supply chain attacks indicates an interest in disrupting or compromising critical business processes. Targeted sectors may include technology, manufacturing, and financial services, where supply chains offer significant opportunities for disruption or gain. The actor's focus on adaptive malware development suggests a desire to remain undetected while maintaining operational effectiveness.
Enhanced Description
CL-STA-1009 is a cyber threat activity cluster associated with the deployment of the Airstalk malware family, which includes both PowerShell and .NET variants. This actor has exhibited a high level of technical sophistication through its use of multi-threaded communication protocols and defense evasion techniques. The .NET variant, in particular, demonstrates advanced capabilities such as complex task execution, versioning mechanisms, and manipulation of PE file timestamps to avoid detection. The malware appears to have been specifically tailored for long-term persistence and intelligence gathering activities. The actor has been linked to supply chain attacks, suggesting a focus on infiltrating critical infrastructure or vendors to achieve broader reach. Airstalk's development timeline can be inferred from timestamp data within the malware samples, indicating a patient and methodical approach.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
CL-STA-1009 has demonstrated a consistent focus on supply chain attacks, with an emphasis on targeting critical infrastructure. The actor’s operational tempo suggests a patient and deliberate approach, with campaigns extending over significant periods to achieve deeper infiltration. Notable past operations may include targeted compromises of software vendors or logistics providers. Campaign activity was first observed in [quarter] 2022, and recent sightings were reported as late as [year]. Victims have included financial services firms and manufacturing companies.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Low confidence in certain details such as the actor's precise motivations and exact campaign history due to limited公开 reporting. The identification of Airstalk malware provides moderate confidence in the threat profile, but further analysis is needed to fully understand the actor's capabilities and targeting patterns.
Iron Tiger
A Tale of Two Targets
No observed data linked yet.
2
Techniques
49
Tools
2
Campaigns
22
IOCs
0
Observed Data
1
Tactics