CL-STA-0048

Aliases: CL STA 0048

Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:22:13

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:in country_code:pk country_code:bd

Context

CL-STA-0048 is a Chinese state-backed APT that targets strategic sectors in South Asia, particularly government and telecommunications entities, with a focus on espionage. The group has been linked to SAP NetWeaver intrusions and employs techniques such as DNS beaconing using ping commands and exploiting unpatched vulnerabilities in services like IIS, Apache Tomcat, and MSSQL. Analysts have observed its use of reverse shell commands and command-and-control traffic directed to specific IP addresses. The actor adapts its methods to evade detection and maintain persistent access to high-value networks.

Exploited vulnerabilities

  • CVE-2025-31324 (vulnerability)

Reports & references

  • Palo Alto Unit 42 — Espionage Campaign Targets South Asian Entities (report)
  • blog.eclecticiq.com — China Nexus Nation State Actors Exploit Sap Netweaver Cve 2025 31324 To Target Critical Infrastructures (report)

External references