TrackBak is an information-stealing malware family observed by Palo Alto Networks Unit 42 in 2025 during cyberespionage intrusions against a government organization in Southeast Asia. In the reported activity, TrackBak was deployed by the China-linked cluster CL-STA-1048, which overlaps with publicly tracked activity associated with Earth Estries, Crimson Palace, and broader China-aligned operations. Unit 42 assessed the overall campaigns as focused on gaining long-term persistent access to sensitive government networks and continuously locating and exfiltrating data.
Based on the reporting, TrackBak functions as an infostealer that collects keystrokes or key logs, clipboard data, network information, and files from drives. One cited sample had SHA256 84e37e42312b9a502c40cf1f3fc181e3ebd4f3e35c58bbf182740dfe38d3b6b9. TrackBak appeared alongside other CL-STA-1048 tooling including EggStremeFuel, EggStreme Loader/Gorem RAT, and Masol RAT, indicating use within a broader espionage toolkit for access, surveillance, and data theft. The exact initial access vector for CL-STA-1048 was reported as unclear.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Masol RAT and EggStreme Loader provided backdoor access, keylogging, and in-memory payload execution, while TrackBak stole keystrokes, clipboard data, and network info.
Masol RAT and EggStreme Loader provided backdoor access, keylogging, and in-memory payload execution, while TrackBak stole keystrokes, clipboard data, and network info.
TrackBak, an information stealer that collects logs, clipboard data, network information, and files from drives.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
TrackBak is an infostealer that performs the following activities: ... Collecting files from drives
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An information stealer that captures keystrokes, clipboard contents, and network information.
Information stealer that collects logs, clipboard data, network information, and files from drives.
Infostealer masquerading as an MS Edge log file to track user activity history. It collects keystrokes, clipboard data, network information, and files from drives.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.