CL-STA-1048
CL-STA-1048 is a China-linked threat activity cluster observed targeting a Southeast Asian government organization from March to September 2025 as part of a broader cyberespionage campaign. Unit 42 reported that the cluster overlaps with publicly documented activity tracked as Earth Estries, also known as Salt Typhoon, and Crimson Palace. The cluster was assessed to be part of an operation focused on gaining long-term persistent access to sensitive government networks and exfiltrating data. Observed CL-STA-1048 tooling included EggStremeFuel, EggStreme Loader (also called Gorem RAT), Masol RAT, TrackBak, and RawCookie. EggStremeFuel/RawCookie was described as a lightweight backdoor using RC4-encrypted command-and-control configuration and supporting file upload and download, directory enumeration, reverse shell control, IP reporting, and C2 configuration updates. EggStreme Loader was used as part of the EggStreme framework to launch Gorem RAT in memory; reported capabilities included extensive backdoor functionality, with one variant supporting file transfer over Dropbox. Masol RAT provided backdoor access, arbitrary command execution, file upload and download, keylogging, configuration updates, and in-memory payload execution. TrackBak was used to steal keystrokes, clipboard data, network information, logs, and files from drives. The cluster employed a multi-payload strategy and stealthy DLL sideloading techniques to maintain access and evade detection. Researchers noted that the use of diverse and sometimes noisy tooling suggested a determined effort to establish a foothold. The exact initial access vector for CL-STA-1048 was not identified in the reporting.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Where they're from
Attributed origin per open-source reporting.
- CN
Tradecraft
12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
9 malware families attributed to this actor across reporting.
4 additional families tracked in Mallory.
Observables
29 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Participated in the 2025 campaign against a Southeast Asian government, using multiple payloads and stealth techniques to maintain persistence and evade detection.
Espionage-focused cluster targeting a Southeast Asian government with multiple payloads for backdoor access, keylogging, reverse shell control, and data theft.
China-aligned activity cluster targeting a Southeast Asian government organization using multiple backdoors, RATs, and stealers to establish persistent access and conduct extensive data theft.
Espionage cluster using multiple payloads and backdoors to establish footholds and evade XDR in a Southeast Asian government network.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.