Also known as: tracked as, HIUPAN, EggStreme Agent, Gorem RAT
CL-STA-1020 targets Southeast Asian government networks, employing AWS Lambda Function URLs configured with AuthType: NONE for stealthy command-and-control communication. The actor has been observed collecting sensitive information from governmental entities, including data on tariffs and trade disputes. An investigation revealed a new Windows backdoor named HazyBeacon, which utilizes this novel C2 technique. This activity cluster has demonstrated significant efforts to remain undetected while executing its operations.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
CL-STA-1020 targets Southeast Asian government networks using stealthy AWS Lambda Function URLs for C2 communication. The actor collects sensitive information like tariffs and trade data, employing a backdoor tool named HazyBeacon to maintain undetected operations.
Goals & Targeting
CL-STA-1020 targets Southeast Asian governments to collect sensitive data on tariffs and trade issues, indicating a focus on economic or geopolitical intelligence. The targeting suggests a strategic interest in influencing policy decisions or gaining competitive advantages in regional trade negotiations.
Enhanced Description
CL-STA-1020 is a threat actor targeting Southeast Asian governmental networks with a focus on collecting sensitive economic data. The actor employs AWS Lambda Function URLs configured with AuthType: NONE for C2 communication, allowing stealthy command and control. An investigation uncovered HazyBeacon, a Windows backdoor tool used for lateral movement and data collection within targeted networks. The actor's primary objectives include gathering information on tariffs and trade disputes, which likely serves political or economic interests.
Key Capabilities
Software / Tooling
Campaigns & Victims
The actor's campaigns demonstrate a focus on Southeast Asian government networks, utilizing sophisticated tools to remain undetected. Notable past operations include the deployment of HazyBeacon for backdoor access and data collection.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence is limited due to missing details like aliases and first seen date. Data gaps include specific campaign details and associated tools beyond HazyBeacon, affecting comprehensive analysis.
No campaigns linked yet.
No observed data linked yet.
40
Techniques
42
Tools
0
Campaigns
40
IOCs
0
Observed Data
13
Tactics