Phantom Taurus is a China-aligned cyber-espionage threat actor assessed to operate in support of People’s Republic of China state interests. The group has been observed for roughly two and a half to three years conducting long-term intelligence collection against government and telecommunications organizations across Africa, the Middle East, and Asia. Its targeting has centered on ministries of foreign affairs, embassies, diplomatic communications, defense-related intelligence, military operations, and other entities tied to geopolitical events and regional security affairs. The actor has also targeted service providers and technology organizations that enable access to government information. Known aliases and prior tracking designations include KTA516 and the temporary cluster identifiers CL-STA-0043 and TGR-STA-0043. Activity associated with the group has also been referred to as Operation Diplomatic Specter. Phantom Taurus is assessed as part of the broader Chinese APT ecosystem based on victimology, capabilities, and shared operational infrastructure, with overlaps noted with infrastructure ecosystems associated with APT27, Winnti, and Mustang Panda. At the same time, its operations appear compartmentalized, and its bespoke tooling has been treated as distinct from those groups. Phantom Taurus primarily pursues espionage through stealthy, persistent access to high-value networks. Reported tradecraft includes compromise of internet-facing Microsoft Exchange and IIS servers, use of known Chinese intrusion tooling such as China Chopper, the Potato suite, and Impacket, and extensive use of living-off-the-land techniques. The actor has demonstrated the ability to maintain access for extended periods, adapt tactics rapidly, and time operations to coincide with major diplomatic, political, or military developments. A notable evolution in the group’s tradecraft was a shift from theft of selected emails on compromised mail servers to direct collection from SQL Server databases. In these operations, Phantom Taurus remotely executed scripts via WMI to run operator-supplied SQL queries and export results for exfiltration, reflecting a more targeted and efficient approach to intelligence gathering. Phantom Taurus is also associated with several customized malware families, including Specter, Ntospy, and the NET-STAR malware suite. NET-STAR is a .NET-based toolkit designed for IIS environments and includes multiple web-based backdoors and in-memory loaders. Reported capabilities include fileless execution within IIS worker processes, encrypted command-and-control, in-memory execution of .NET assemblies, database interaction, arbitrary code execution, web shell management, timestomping, and in newer variants, AMSI and ETW bypasses. These features indicate a strong emphasis on stealth, persistence, and anti-forensic evasion in heavily monitored environments. Overall, Phantom Taurus is a covert and capable PRC-linked espionage actor focused on sustained access to strategically important targets and the theft of sensitive non-public information relevant to Chinese geopolitical and economic priorities.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
14 malware families attributed to this actor across reporting.
9 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
"...prior intrusions have weaponized vulnerable on-premises Internet Information Services (IIS) and Microsoft Exchange servers, abusing flaws like ProxyLogon and ProxyShell, to infiltrate target networks."
"...prior intrusions have weaponized vulnerable on-premises Internet Information Services (IIS) and Microsoft Exchange servers, abusing flaws like ProxyLogon and ProxyShell, to infiltrate target networks."
4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Targeting African government and related service providers, with emphasis on diplomatic communications, defense intelligence, and critical ministry operations.
Phantom Taurus is a Chinese nation-state threat actor conducting cyber-espionage campaigns targeting high-value government and military entities in Africa, the Middle East, and Asia, using custom toolkits.
Chinese nexus APT conducting long-term espionage against government and telecommunications sectors using the NET-STAR malware suite.
Named APT/activity cluster described as a China-linked nexus, associated with discovery/use of the NET-STAR malware suite.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.