CL-STA-1020 is a cyber threat actor targeting Southeast Asian governments to steal sensitive data using the HazyBeacon backdoor.
Analyst brief
CL-STA-1020 is an unknown threat actor targeting Southeast Asian government networks, focusing on stealing sensitive information such as tariffs and trade dispute data. Their key TTP involves using a novel Windows backdoor named HazyBeacon, which leverages AWS Lambda Function URLs configured with AuthType: NONE for stealthy command-and-control communication. Defenders should monitor for anomalous traffic to unauthenticated AWS Lambda Function URLs and investigate any indications of the HazyBeacon backdoor to detect this persistent and evasive activity.
CL-STA-1020
unknown
CL-STA-1020 targets Southeast Asian government networks, employing AWS Lambda Function URLs configured with AuthType: NONE for stealthy command-and-control communication. The actor has been observed collecting sensitive information from governmental entities, including data on tariffs and trade disputes. An investigation revealed a new Windows backdoor named HazyBeacon, which utilizes this novel C2 technique. This activity cluster has demonstrated significant efforts to remain undetected while executing its operations.