Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors CL-STA-1020

Also known as: tracked as, HIUPAN, EggStreme Agent, Gorem RAT

Description

CL-STA-1020 targets Southeast Asian government networks, employing AWS Lambda Function URLs configured with AuthType: NONE for stealthy command-and-control communication. The actor has been observed collecting sensitive information from governmental entities, including data on tariffs and trade disputes. An investigation revealed a new Windows backdoor named HazyBeacon, which utilizes this novel C2 technique. This activity cluster has demonstrated significant efforts to remain undetected while executing its operations.

Goals & Targeting

Targeted Sectors

Government
Media
Critical infrastructure
Defense
Utilities
Energy

Targeted Countries / Regions

US
CN
SG
IL

AI Analysis

· 1 week ago

Executive Summary

CL-STA-1020 targets Southeast Asian government networks using stealthy AWS Lambda Function URLs for C2 communication. The actor collects sensitive information like tariffs and trade data, employing a backdoor tool named HazyBeacon to maintain undetected operations.

Goals & Targeting

CL-STA-1020 targets Southeast Asian governments to collect sensitive data on tariffs and trade issues, indicating a focus on economic or geopolitical intelligence. The targeting suggests a strategic interest in influencing policy decisions or gaining competitive advantages in regional trade negotiations.

Enhanced Description

CL-STA-1020 is a threat actor targeting Southeast Asian governmental networks with a focus on collecting sensitive economic data. The actor employs AWS Lambda Function URLs configured with AuthType: NONE for C2 communication, allowing stealthy command and control. An investigation uncovered HazyBeacon, a Windows backdoor tool used for lateral movement and data collection within targeted networks. The actor's primary objectives include gathering information on tariffs and trade disputes, which likely serves political or economic interests.

Key Capabilities

  • Use of AWS Lambda Function URLs for C2 communication
  • Deployment of HazyBeacon backdoor tool
  • Stealthy data exfiltration techniques

Software / Tooling

HazyBeacon
Custom AWS Lambda Function

Campaigns & Victims

The actor's campaigns demonstrate a focus on Southeast Asian government networks, utilizing sophisticated tools to remain undetected. Notable past operations include the deployment of HazyBeacon for backdoor access and data collection.

IOC Patterns

  • AWS Lambda Function URLs with AuthType: NONE
  • Presence of HazyBeacon backdoor tool in Windows environments

Recommended Actions

  • Monitor and secure AWS services against unauthorized access
  • Implement network traffic analysis to detect unusual C2 patterns
  • Regularly audit and patch systems to prevent backdoor installations

Suggested Tags

APT
espionage
government

Confidence Assessment

Confidence is limited due to missing details like aliases and first seen date. Data gaps include specific campaign details and associated tools beyond HazyBeacon, affecting comprehensive analysis.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 3 Filename 6 SHA-256 Hash 11

References

  1. unit42.paloaltonetworks.com — Cited by web research for: HIUPAN
  2. attack.mitre.org — Cited by web research for: T1213
  3. attack.mitre.org — Cited by web research for: T1059
  4. unit42.paloaltonetworks.com — Cited by web research for: Google Drive

Intel Summary

40

Techniques

42

Tools

0

Campaigns

40

IOCs

0

Observed Data

13

Tactics

Tags

Backdoor / C2
Government Targeting
APT
espionage
government

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
60%
Added
Jul 5, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.