CL-STA-0043

Aliases: TGR-STA-0043

First seen
2021-06-15 00:00:00
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 11:50:45

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:ae country_code:sa country_code:eg

Context

CL-STA-0043 is a highly skilled and sophisticated threat actor, believed to be a nation-state, targeting governmental entities in the Middle East and Africa. They exploit vulnerabilities in on-premises Internet Information Services and Microsoft Exchange servers to infiltrate target networks. They engage in reconnaissance, locate vital assets, and have been observed using native Windows tools for privilege escalation.

Malware & tools used

Reports & references

  • securonix.com — Securonix Threat Labs Monthly Intelligence Insights June 2023 (report)
  • paloaltonetworks.com — Through The Cortex Xdr Lens Uncovering A New Activity Group Targeting Governments In The Middle East And Africa (report)
  • Palo Alto Unit 42 — Operation Diplomatic Specter (report)
  • Palo Alto Unit 42 — Phantom Taurus (report)

External references