CL-STA-0048 is a China-linked, state-backed APT espionage cluster tracked by Palo Alto Networks Unit 42. Unit 42 assessed with moderate-high confidence that the actor originates in China and characterized it as a nation-state espionage campaign. The group has targeted high-value organizations in South Asia, including a telecommunications organization, and has also been reported targeting SAP NetWeaver instances in critical infrastructure and government-related environments in the UK, US, and Saudi Arabia via exploitation of CVE-2025-31324. Reported objectives include theft of personal information of government employees and sensitive organizational data. Observed tradecraft includes systematic exploitation attempts against internet-facing IIS, Apache Tomcat/ColdFusion, MSSQL, and SAP NetWeaver systems; deployment of web shells; PowerShell-based reconnaissance; DNS exfiltration and beaconing using ping with hex-encoded subdomain queries; use of PlugX as a primary backdoor; Cobalt Strike; SoftEther VPN; Winos4.0-based malware; Stowaway; SspiUacBypass; and privilege-escalation tooling from the Potato Suite, including BadPotato and RasmanPotato. Unit 42 also documented a rare payload delivery technique it calls Hex Staging, in which hex-encoded payload chunks are written incrementally and decoded with certutil. In MSSQL-focused activity, the actor enumerated databases, searched for phone-related fields, attempted to create a privileged SQL user, and sought to exfiltrate PII and sensitive client data. In SAP NetWeaver intrusions, reporting states CL-STA-0048 exploited CVE-2025-31324 to upload web shells and issue thousands of malicious commands for network discovery and SAP-specific application mapping, likely in preparation for lateral movement. EclecticIQ linked CL-STA-0048 to webshell persistence, reverse shell activity, and DNS-based beaconing, and reported overlap with infrastructure previously associated with exploitation of Ivanti CSA vulnerabilities. Separate reporting noted overlaps in post-exploitation tactics with other China-linked IIS-focused activity, including use of ping for DNS beaconing and shared infrastructure. Known overlaps or associations mentioned in the content include DragonRank-linked PlugX activity and concurrent SAP NetWeaver targeting alongside UNC5221 and UNC5174. No additional aliases beyond CL-STA-0048 were provided in the content.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
31 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
39 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-linked cluster targeting IIS servers and using hex-encoded DNS subdomain queries for data exfiltration.
China-aligned threat cluster previously observed singling out IIS web servers; noted as tactically close to OP-512.
CL-STA-0048 is a Chinese APT group reported to be exploiting SAP NetWeaver CVE-2025-31324, targeting critical infrastructure and enterprise systems.
Chinese APT group conducting reconnaissance and lateral movement preparation in SAP NetWeaver environments.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.