CL-STA-1020
- Primary motivation
- espionage
- Sophistication
- advanced
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:29:42
Targeted industries: government-and-public-sector
Context
CL-STA-1020 targets Southeast Asian government networks, employing AWS Lambda Function URLs configured with AuthType: NONE for stealthy command-and-control communication. The actor has been observed collecting sensitive information from governmental entities, including data on tariffs and trade disputes. An investigation revealed a new Windows backdoor named HazyBeacon, which utilizes this novel C2 technique. This activity cluster has demonstrated significant efforts to remain undetected while executing its operations.
Reports & references
- blog.qualys.com — Hazybeacon Aws Lambda Function Url Command Control Abuse (report)
- Palo Alto Unit 42 — Windows Backdoor For Novel C2 Communication (report)