CL-STA-0043
Aliases: TGR-STA-0043
- First seen
- 2021-06-15 00:00:00
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 11:50:45
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:ae country_code:sa country_code:eg
Context
CL-STA-0043 is a highly skilled and sophisticated threat actor, believed to be a nation-state, targeting governmental entities in the Middle East and Africa. They exploit vulnerabilities in on-premises Internet Information Services and Microsoft Exchange servers to infiltrate target networks. They engage in reconnaissance, locate vital assets, and have been observed using native Windows tools for privilege escalation.
Malware & tools used
- NET-STAR (malware)
Reports & references
- securonix.com — Securonix Threat Labs Monthly Intelligence Insights June 2023 (report)
- paloaltonetworks.com — Through The Cortex Xdr Lens Uncovering A New Activity Group Targeting Governments In The Middle East And Africa (report)
- Palo Alto Unit 42 — Operation Diplomatic Specter (report)
- Palo Alto Unit 42 — Phantom Taurus (report)