Phantom Taurus, a newly identified advanced persistent threat (APT) group linked to the People’s Republic of China, has been conducting extensive cyber espionage operations over the past two and a half years. The group has primarily targeted government and telecommunications organizations across Africa, the Middle East, and Asia, focusing on ministries of foreign affairs, embassies, and entities involved in geopolitical and military affairs. Phantom Taurus is distinguished by its use of highly covert tactics, techniques, and procedures (TTPs) that enable it to maintain persistent, long-term access to sensitive networks. The group’s primary objective is intelligence gathering, with a particular interest in diplomatic communications, defense-related information, and the operations of critical governmental ministries. Researchers from Palo Alto Networks Unit 42 first observed this activity cluster in June 2023, initially tracking it as CL-STA-0043. In May 2024, the cluster was promoted to a temporary group, TGR-STA-0043, under the campaign name Operation Diplomatic Specter, reflecting the sustained and sophisticated nature of the attacks. Continued investigation and intelligence collection led to the formal classification of Phantom Taurus as a distinct threat actor, based on a rigorous attribution framework. One of the group’s notable tools is NET-STAR, a previously undocumented custom malware suite designed for stealthy operations and long-term persistence. The timing and scope of Phantom Taurus’ operations often align with major global and regional security events, suggesting a strategic intent to support Chinese state interests. The group’s ability to rapidly adapt its TTPs has allowed it to evade detection and maintain access to high-value targets. Phantom Taurus’ campaigns are characterized by their focus on espionage rather than financial gain or disruption. The group’s activities have provided China with access to confidential data of strategic economic and geopolitical value. The discovery of Phantom Taurus and its NET-STAR malware suite highlights the evolving landscape of Chinese cyber espionage and the increasing sophistication of state-sponsored threat actors. The group’s operations underscore the need for heightened vigilance and advanced defensive measures among government and telecommunications organizations in the targeted regions. The identification and public disclosure of Phantom Taurus mark a significant development in the understanding of Chinese cyber operations. Security researchers emphasize the importance of continued monitoring and intelligence sharing to counter the persistent threat posed by Phantom Taurus and similar APT groups. The campaign demonstrates the ongoing risk to critical infrastructure and sensitive government communications from nation-state actors employing advanced malware and covert techniques.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
Alongside the naming of Phantom Taurus on September 30, 2025, Unit 42 released technical analysis of the NET-STAR malware suite, including component descriptions, tradecraft details, and SHA-256 indicators of compromise. The company also said it had detections, mitigations, and intelligence sharing in place for defenders and Cyber Threat Alliance members.
On September 30, 2025, Palo Alto Networks Unit 42 publicly identified the previously undocumented cluster as Phantom Taurus after maturing its internal tracking from CL-STA-0043 and TGR-STA-0043. The report described the group as a distinct China-nexus espionage actor with operational compartmentalization and long-term intelligence objectives.
During recent intrusions in 2025, Phantom Taurus used a previously undocumented .NET malware suite called NET-STAR against internet-facing IIS servers. The suite included the fileless IIServerCore backdoor and in-memory loader variants, with features such as encrypted command-and-control, timestomping, and in newer versions AMSI and ETW bypasses.
In early 2025, researchers observed the actor expand from stealing emails on compromised Exchange servers to directly querying Microsoft SQL Server databases. The group used a custom batch script, mssq.bat, executed remotely via WMI with stolen credentials to export data to CSV for exfiltration.
In May 2024, Unit 42 elevated the activity to temporary group TGR-STA-0043, also referred to as Operation Diplomatic Specter, after additional collection and attribution work. The China nexus was strengthened by infrastructure overlaps with groups such as APT27, Winnti, and Mustang Panda, as well as code similarities to Ghost RAT-linked tooling.
Unit 42 first observed the activity in June 2023 and tracked it as CL-STA-0043. The intrusions involved covert, persistent access to foreign ministries, embassies, and related entities for intelligence collection.
In 2022, Phantom Taurus allegedly compromised Microsoft Exchange servers belonging to foreign ministries involved in the China-Arab summit in Riyadh. Researchers said the actor searched mailboxes for summit-related terms and names including Xi Jinping and Peng Liyuan.
Palo Alto Networks Unit 42 assessed that the China-aligned espionage activity later named Phantom Taurus had been active since at least late 2022, targeting government and telecommunications organizations across Africa, the Middle East, and Asia. Its objectives centered on diplomatic communications, foreign affairs, and defense-related intelligence aligned with PRC interests.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
17 references tracked. Mallory keeps watching after this page renders.
linkedin.com
Open sourcesecurityaffairs.com
Open sourceinfosecurity-magazine.com
Open sourcego.theregister.com
Open sourcecyberscoop.com
Open sourcedarkreading.com
Open sourcethehackernews.com
Open sourcebankinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.