logo

Behind the Clouds: Attackers Targeting Governments in Southeast Asia Implement Novel Covert C2 Communication

ID: e9c07a9e-c94d-5595-836e-9f6ee9083c0d

STIX ID: report--e9c07a9e-c94d-5595-836e-9f6ee9083c0d

Feed Name: Palo Alto Networks Unit 42

Threat Score
86/100

Date Published: 2025-07-14

Date Updated: 2026-04-28

Author: Lior Rochberger

...
...

Unit 42 tracked CL-STA-1020, an APT campaign targeting Southeast Asian government entities that deployed a novel Windows backdoor called HazyBeacon which uses DLL sideloading for persistence and abuses AWS Lambda function URLs as a covert C2 channel; attackers collected trade-related documents and attempted exfiltration via Google Drive and Dropbox, and the report includes technical analysis, IoCs (SHA256 hashes), and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.