Palo Alto Networks spots new China espionage group showcasing advanced skills
ID: 7cf0b5d3-7389-5ce1-996d-9ebc534be9e6
STIX ID: report--7cf0b5d3-7389-5ce1-996d-9ebc534be9e6
Feed Name: CyberScoop
Unit 42 has identified a previously undocumented China-linked espionage group called Phantom Taurus that has compromised nearly ten high-value targets (ministries of foreign affairs, embassies, diplomats, and telecom networks) across the Middle East, Africa, and Asia. The group uses a bespoke NET-STAR malware suite with stealthy in-memory and .NET payload techniques, maintains long-term opportunistic access—sometimes for nearly two years—and commonly gains initial access by exploiting unpatched internet-facing devices; Unit 42 published TTPs, indicators, and malware analysis to enable detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
