CL-STA-0048 is a China-linked, state-backed cyber-espionage cluster tracked by Palo Alto Networks Unit 42. It has targeted high-value South Asian telecommunications organizations and government agencies, with objectives including collection of government-employee personal information and sensitive organizational and database data. The actor has also been linked to exploitation of SAP NetWeaver Visual Composer vulnerabilities, including CVE-2025-31324, alongside other China-nexus espionage clusters. CL-STA-0048 gains access by targeting exposed IIS, Apache Tomcat, Microsoft SQL Server, and SAP NetWeaver services. Following compromise, it conducts host, network, database, and SAP-application reconnaissance using PowerShell, command-shell utilities, SQL tooling, and large volumes of discovery commands. The actor has used PlugX, Cobalt Strike, Winos4.0-based malware, SoftEther VPN, Stowaway, iox, Potato Suite privilege-escalation utilities, and SspiUacBypass. It employs DLL sideloading and process injection, including injection of Cobalt Strike into legitimate processes, and has attempted LSASS credential dumping. The cluster uses native utilities such as certutil and hexadecimal payload staging to reduce detection opportunities. It establishes persistence by creating privileged SQL database accounts and deploys proxy and tunneling tools to enable access through compromised hosts. CL-STA-0048 searches databases for personally identifiable and sensitive client data, stages collected results, and exfiltrates data over command-and-control infrastructure, including DNS-based channels implemented through encoded subdomain queries and ping-triggered lookups. Chinese-language tooling, operational patterns aligned with the UTC+8 time zone, and infrastructure and tradecraft overlaps support its China nexus.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
38 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
39 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a Chinese espionage group previously observed exploiting SAP product vulnerabilities, specifically CVE-2025-31324 affecting SAP products including SAP NetWeaver.
Referenced as a China-nexus espionage cluster previously observed weaponizing SAP product flaws including CVE-2025-31324.
China-linked cluster targeting IIS servers and using hex-encoded DNS subdomain queries for data exfiltration.
China-aligned threat cluster previously observed singling out IIS web servers; noted as tactically close to OP-512.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.