Uptime Hamster: 58d 11h 26mDeploy: 3 Aug 2026 06:56Updated: 2026-07-21
Logo del actor de amenaza CL-STA-0043

CL-STA-0043

0 incidentes 0 paises 0 sectores apt CN Ultimo: -
Aliases: TGR-STA-0043
Ver en IntelTracker → APTTrail →
CL-STA-0043, also known as TGR-STA-0043 or Phantom Taurus, is a Chinese state-aligned advanced persistent threat (APT) group that first emerged in late 2022, focusing on cyber-espionage operations. The group's primary motivation is information theft and espionage, targeting political entities, government organizations, and high-value corporate sectors globally. CL-STA-0043 is characterized by meticulous planning, targeting precision, and a willingness to persist in operations even after detection, often resurfacing within hours or days of exposure. They employ rare email exfiltration techniques, a unique credential theft method involving network providers, and have adopted the Yasso penetration testing toolset. Originally tracked as a cluster of activity, the group was formally classified as a temporary group (TGR-STA-0043) in May 2024 and later as a new threat actor (Phantom Taurus) in September 2025, reflecting a maturation in understanding its distinct and persistent operations.

Aliases del actor

TGR-STA-0043

Actores similares

blackbastaransomware · 523mosesstaffactor · 2BlackBastaactor · 2mustang-pandaactor · 1stardust-chollimaactor · 1static-spideractor · 1pakistanactor · 1kasakhstanactor · 1apt-deathstalkeractor · 1apt-moustachedbounceractor · 1
Motivacion