HazyBeacon is a previously undocumented Windows backdoor associated with the CL-STA-1020 cyber-espionage cluster and used in operations targeting government entities in Southeast Asia since at least late 2024. The campaign has been assessed as focused on covert intelligence collection, including theft of sensitive government information related to tariffs and trade disputes.
On compromised Windows systems, HazyBeacon operates as a lightweight backdoor that profiles the host, establishes command-and-control over HTTPS, receives remote commands, and downloads additional payloads. A notable characteristic of the campaign is its use of AWS Lambda Function URLs as command-and-control relays, allowing malicious traffic to blend with legitimate communications to Amazon infrastructure. Reporting also indicates the broader operation abused compromised AWS accounts and publicly accessible Lambda Function URLs, relying on weak cloud identity and configuration practices rather than vulnerabilities in AWS itself.
Initial execution on victim hosts has been linked to DLL sideloading using a legitimate Microsoft .NET executable to load a malicious DLL. Persistence was maintained through creation of a Windows service so the backdoor would relaunch after reboot. After establishing command-and-control, operators deployed follow-on tooling for file collection and staging. Observed post-compromise activity included targeted file discovery, collection of documents matching selected extensions and time ranges, archive creation and splitting, and attempted exfiltration through common cloud storage services. Additional reporting attributes to HazyBeacon capabilities including remote command execution, document theft, and keystroke capture.
HazyBeacon exemplifies a cloud-enabled espionage tradecraft model in which trusted third-party infrastructure is repurposed to conceal command-and-control and complicate detection. Its targeting, stealthy command channel design, and follow-on collection behavior are consistent with a state-aligned intelligence-gathering operation against Southeast Asian government networks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A malicious campaign attributed to the group “CL-STA-1020” has been observed targeting government agencies in Southeast Asia, leveraging a previously undocumented Windows backdoor, dubbed HazyBeacon.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
Attackers exploit stolen IAM credentials to create Lambda functions in compromised AWS accounts.
HazyBeacon is a lightweight backdoor that profiles systems, executes remote commands, and exfiltrates data, including documents and keystrokes.
Attackers exploit stolen IAM credentials to create Lambda functions in compromised AWS accounts.
Attackers exploit stolen IAM credentials to create Lambda functions in compromised AWS accounts.
Relay setup: Public Function URLs are enabled for command transmission. C2 communication: Malware sends encrypted requests to Lambda, which forwards them to attacker-controlled servers and relays responses back.
HazyBeacon is a lightweight backdoor that profiles systems, executes remote commands, and exfiltrates data, including documents and keystrokes.
This backdoor leverages a novel C2 technique in which the backdoor establishes C2 communication via AWS Lambda URLs.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A lightweight backdoor used in a cyber-espionage campaign that profiles systems, executes remote commands, and exfiltrates data including documents and keystrokes. It hides C2 traffic behind AWS Lambda Function URLs hosted on trusted AWS infrastructure.
Ранее не задокументированный бэкдор, использующий AWS Lambda URLs для маскировки C2-трафика под легитимные обращения к amazonaws.com.
A lightweight Windows backdoor used in a campaign targeting government networks in Southeast Asia. It collects host details, receives encrypted commands to execute shell instructions or download additional payloads, and uploads stolen documents and captured keystrokes. Its command-and-control traffic is relayed through attacker-abused AWS Lambda Function URLs hosted in compromised AWS accounts.
State-backed Windows backdoor using AWS Lambda for data theft from Southeast Asian government targets (per summary).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.