logo

Palo Alto Networks spots new China espionage group showcasing advanced skills

ID: 7cf0b5d3-7389-5ce1-996d-9ebc534be9e6

STIX ID: report--7cf0b5d3-7389-5ce1-996d-9ebc534be9e6

Feed Name: CyberScoop

Threat Score
88/100

Date Published: 2025-09-30

Date Updated: 2026-04-21

Author: Matt Kapko

...
...

Unit 42 has identified a previously undocumented China-linked espionage group called Phantom Taurus that has compromised nearly ten high-value targets (ministries of foreign affairs, embassies, diplomats, and telecom networks) across the Middle East, Africa, and Asia. The group uses a bespoke NET-STAR malware suite with stealthy in-memory and .NET payload techniques, maintains long-term opportunistic access—sometimes for nearly two years—and commonly gains initial access by exploiting unpatched internet-facing devices; Unit 42 published TTPs, indicators, and malware analysis to enable detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.