CL-STA-1020 is a state-backed cyber-espionage cluster tracked for operations against government organizations in Southeast Asia during 2024 and 2025. The actor is associated with the HazyBeacon campaign, which used a previously undocumented Windows backdoor for intelligence collection, with reporting indicating a focus on sensitive government information including material related to trade disputes. The group’s tradecraft includes DLL sideloading to launch HazyBeacon through a legitimate Microsoft .NET executable, persistence via creation of a Windows service, and command execution and payload delivery through the backdoor. The malware has been described as collecting host information, receiving encrypted commands, downloading additional payloads, and supporting theft of documents and captured keystrokes. Post-compromise activity included file discovery and collection using an auxiliary payload, staging data into archives, and exfiltration through cloud storage services. A notable feature of the campaign is command-and-control relaying through abused Amazon Web Services infrastructure, specifically public AWS Lambda Function URLs hosted in compromised third-party AWS accounts. This allowed malicious traffic to blend with routine encrypted connections to trusted cloud infrastructure and added a defense-evasion layer to the operation. The actor’s use of legitimate services for both command-and-control and exfiltration reflects a stealth-focused espionage workflow rather than disruptive or financially motivated operations. The cluster identifier indicates an analytically grouped activity set rather than a publicly established historical intrusion set with broadly adopted alternative names. No corroborated sub-groups or widely used aliases are established beyond CL-STA-1020 and the associated HazyBeacon campaign name.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
7 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Activity cluster targeting Southeast Asian government organizations and using the HazyBeacon backdoor with command-and-control over AWS Lambda URLs to blend with legitimate cloud traffic.
Cloud-native intrusion campaign targeting government networks in Southeast Asia by abusing compromised AWS accounts and Lambda Function URLs as covert command-and-control relays for a lightweight backdoor.
State-backed cluster targeting Southeast Asian government organizations using the HazyBeacon backdoor and AWS Lambda for data theft.
Conducting an intelligence-gathering campaign against government agencies in Southeast Asia using the HazyBeacon Windows backdoor, DLL sideloading, Windows service persistence, AWS Lambda URL-based command-and-control, file collection, and exfiltration via cloud storage services.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.