Friday, August 14, 2026
LIVE
Israeli Authorities Charge Settler with Manslaughter over Death of Palestinian Activist///United Nations Report Documents Deliberate Attacks on Civilians in Myanmar///Palestinian Families in Qusra Remain Under Settler Siege for Sixth Day///Israeli Prime Minister Rejects New United States Proposal for Gaza Peace///Houthi Forces Strike Mocha Port on Yemen Red Sea Coast///Satellite Analysis Examines Potential Impact of Strikes on Iranian Facility///United Nations Renews Calls for Civilian Protection Amid Ongoing Sudan Conflict///New Commercial Quay Begins Operations at Syria Port of Tartous///US Threatens Economic Pressure on Iran After New Tanker Attacks///Rising West Bank Settler Violence Framed as Retaliation by Residents///Mass funeral held in Gaza for families killed in 2023 strike///Concerns Mount Over United States Missile Inventories Amid Iran Conflict Pause///Israeli Authorities Charge Settler with Manslaughter over Death of Palestinian Activist///United Nations Report Documents Deliberate Attacks on Civilians in Myanmar///Palestinian Families in Qusra Remain Under Settler Siege for Sixth Day///Israeli Prime Minister Rejects New United States Proposal for Gaza Peace///Houthi Forces Strike Mocha Port on Yemen Red Sea Coast///Satellite Analysis Examines Potential Impact of Strikes on Iranian Facility///United Nations Renews Calls for Civilian Protection Amid Ongoing Sudan Conflict///New Commercial Quay Begins Operations at Syria Port of Tartous///US Threatens Economic Pressure on Iran After New Tanker Attacks///Rising West Bank Settler Violence Framed as Retaliation by Residents///Mass funeral held in Gaza for families killed in 2023 strike///Concerns Mount Over United States Missile Inventories Amid Iran Conflict Pause///
Subscribe
The Levant
Independent · Digital
The Levant Herald
PoliticsAI-assisted

New Chinese Nexus APT Group Targeting Organizations to Deploy NET-STAR Malware Suite

## Cybersecurity Update: Phantom Taurus APT Group

Cybersecurity Update: Phantom Taurus APT Group

China-linked advanced persistent threat (APT) group, Phantom Taurus, has intensified espionage operations against government and telecommunications targets in Africa, the Middle East, and Asia. They are utilizing a newly discovered .NET malware suite called NET-STAR.

Initially tracked by Unit 42 in June 2023 as cluster CL-STA-0043, and temporarily designated TGR-STA-0043 in May 2024, the group is now formally recognized as a distinct threat actor aligned with the People’s Republic of China's state interests.

Distinctive Tactics, Techniques, and Procedures

Phantom Taurus distinguishes itself through unique, custom-developed tactics, techniques, and procedures (TTPs) that enable highly covert, persistent operations. While sharing some infrastructure with other Chinese APTs, such as APT27, Winnti, and Mustang Panda, Phantom Taurus uses exclusive components not observed in other campaigns.

Unit 42’s attribution framework guided the evolution of CL-STA-0043 from a loosely defined activity cluster to the formally recognized APT group Phantom Taurus.

In early 2025, Phantom Taurus transitioned from an email-centric compromise approach to direct database targeting. Using a custom script called mssq.bat, the group connects to SQL Server instances using stolen credentials, issues dynamic queries, and exports results to CSV files. Execution is managed through Windows Management Instrumentation (WMI), enabling remote, in-memory execution within compromised environments.

China-linked advanced persistent threat (APT) group, Phantom Taurus, has intensified espionage operations against government and telecommunications targets in Africa, the Middle East, and Asia.
Omar Sabbagh · The Levant Herald

Introducing NET-STAR: A .NET Malware Suite

NET-STAR, a previously undocumented malware suite, has been identified as targeting Internet Information Services (IIS) web servers. It comprises three .NET-based components:

IIServerCore: A modular, fileless backdoor executed in memory within the w3wp.exe IIS worker process. AssemblyExecuter V1: A loader that executes .NET assemblies in memory, evading disk-based detection mechanisms. AssemblyExecuter V2: An advanced variant that bypasses AMSI and ETW, allowing stealthy operations in heavily monitored environments.

Phantom Taurus employs timestomping techniques to evade forensic analysis, modifying file timestamps on web shells and backdoor components.

Advertisement

Organizations operating IIS web services, as well as ministries, embassies, and telecommunications providers in high-interest regions, should consider the following measures:

Implement robust monitoring of w3wp.exe memory operations and unusual ASPX file activities. Enforce least-privilege SQL accounts and rotate administrative credentials to prevent database exfiltration scripts like mssq.bat. Deploy Endpoint Detection and Response (EDR) solutions that inspect in-memory .NET execution and detect AMSI/ETW bypass attempts.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories