CL-STA-0043 (Phantom Taurus) is a Chinese state-nexus cyber-espionage actor targeting government and telecommunications organizations.
Analyst brief
CL-STA-0043 (Phantom Taurus) is a Chinese state-nexus cyber-espionage actor. It targets government and telecommunications organizations, including ministries of foreign affairs and diplomatic missions, across Africa, the Middle East and Asia. The actor gains initial access by exploiting internet-facing IIS and Microsoft Exchange servers, then conducts reconnaissance. Defenders should focus on ensuring these servers are patched and monitor for suspicious web-shell activity.
CL-STA-0043
Phantom TaurusTGR-STA-0043
unknown
CL-STA-0043 is a Chinese state-nexus cyber-espionage actor tracked by Palo Alto Networks Unit 42, which promoted the activity cluster to the named threat actor Phantom Taurus in September 2025, having previously designated it TGR-STA-0043 and linked it to the Operation Diplomatic Specter campaign. The group targets government and telecommunications organizations, including ministries of foreign affairs, embassies and diplomatic missions, across Africa, the Middle East and Asia, with a focus on geopolitical and military intelligence collection. It typically gains access by exploiting internet-facing Internet Information Services (IIS) and Microsoft Exchange servers, then performs reconnaissance and privilege escalation using native Windows tooling. In more recent operations the actor deployed NET-STAR, a fileless .NET malware suite targeting IIS web servers that comprises the IIServerCore backdoor and the AssemblyExecuter V1 and V2 loaders.
How does CL-STA-0043 (Phantom Taurus) typically gain initial access to a network?+
It exploits vulnerabilities in internet-facing IIS and Microsoft Exchange servers.
Which sectors are primarily targeted by this actor?+
It targets government and telecommunications organizations, including ministries of foreign affairs and diplomatic missions, across Africa, the Middle East and Asia.