CL-STA-0002 is a threat activity cluster associated with a series of apparently related intrusions against organizations in the Middle East, Africa, and the United States. The activity has been assessed with medium confidence as nation-state-aligned based on victimology, tradecraft, and the use of customized tooling, although no specific sponsoring state or publicly established intrusion set has been conclusively attributed. The cluster is characterized by a bespoke toolset used for covert access, credential theft, and data exfiltration. Its malware includes Agent Racoon, a .NET backdoor that uses DNS as a covert command-and-control channel and supports command execution plus file upload and download; Ntospy, a custom Network Provider credential theft module that hijacks Windows authentication flows to capture user credentials; and Mimilite, a reduced customized Mimikatz variant used to dump credentials. In observed intrusions, Agent Racoon was executed via scheduled tasks rather than providing persistence natively. Operational tradecraft includes staging tools from temporary directories, masquerading binaries and stored data as legitimate Microsoft or update-related artifacts, and using cleanup utilities after interactive activity to reduce forensic residue. The actor also used PowerShell and batch scripts during operations, collected email from Microsoft Exchange environments through PowerShell snap-ins, and exfiltrated user data such as roaming profiles using archived multi-part collections. Reported overlaps with CL-STA-0043 include shared malware lineage and common victim organizations, suggesting either a related operator set, shared tooling, or a broader campaign ecosystem. At a capability level, CL-STA-0002 demonstrates initial access and post-compromise operations consistent with espionage-oriented intrusion activity, including credential theft, persistence through scheduled execution, command-and-control over covert channels, defense evasion through masquerading and cleanup, and exfiltration of confidential information.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.