New Chinese Nexus APT Group Targeting Organizations to Deploy NET-STAR Malware Suite
## Cybersecurity Update: Phantom Taurus APT Group
Cybersecurity Update: Phantom Taurus APT Group
China-linked advanced persistent threat (APT) group, Phantom Taurus, has intensified espionage operations against government and telecommunications targets in Africa, the Middle East, and Asia. They are utilizing a newly discovered .NET malware suite called NET-STAR.
Initially tracked by Unit 42 in June 2023 as cluster CL-STA-0043, and temporarily designated TGR-STA-0043 in May 2024, the group is now formally recognized as a distinct threat actor aligned with the People’s Republic of China's state interests.
Distinctive Tactics, Techniques, and Procedures
Phantom Taurus distinguishes itself through unique, custom-developed tactics, techniques, and procedures (TTPs) that enable highly covert, persistent operations. While sharing some infrastructure with other Chinese APTs, such as APT27, Winnti, and Mustang Panda, Phantom Taurus uses exclusive components not observed in other campaigns.
Unit 42’s attribution framework guided the evolution of CL-STA-0043 from a loosely defined activity cluster to the formally recognized APT group Phantom Taurus.
In early 2025, Phantom Taurus transitioned from an email-centric compromise approach to direct database targeting. Using a custom script called mssq.bat, the group connects to SQL Server instances using stolen credentials, issues dynamic queries, and exports results to CSV files. Execution is managed through Windows Management Instrumentation (WMI), enabling remote, in-memory execution within compromised environments.
China-linked advanced persistent threat (APT) group, Phantom Taurus, has intensified espionage operations against government and telecommunications targets in Africa, the Middle East, and Asia.
Introducing NET-STAR: A .NET Malware Suite
NET-STAR, a previously undocumented malware suite, has been identified as targeting Internet Information Services (IIS) web servers. It comprises three .NET-based components:
IIServerCore: A modular, fileless backdoor executed in memory within the w3wp.exe IIS worker process. AssemblyExecuter V1: A loader that executes .NET assemblies in memory, evading disk-based detection mechanisms. AssemblyExecuter V2: An advanced variant that bypasses AMSI and ETW, allowing stealthy operations in heavily monitored environments.
Phantom Taurus employs timestomping techniques to evade forensic analysis, modifying file timestamps on web shells and backdoor components.
Organizations operating IIS web services, as well as ministries, embassies, and telecommunications providers in high-interest regions, should consider the following measures:
Implement robust monitoring of w3wp.exe memory operations and unusual ASPX file activities. Enforce least-privilege SQL accounts and rotate administrative credentials to prevent database exfiltration scripts like mssq.bat. Deploy Endpoint Detection and Response (EDR) solutions that inspect in-memory .NET execution and detect AMSI/ETW bypass attempts.
Based on reporting by GBHackers.




