A new cyber actor aligned with the Chinese state, called Phantom Taurus, has emerged as a significant threat in the cybersecurity landscape. For more than two and a half years, this group has carried out attacks focused on the espionage of government entities in Africa, the Middle East, and Asia, concentrating on the collection of confidential data of strategic interest to China.
Stealthy Cyberattacks
Palo Alto Networks investigations, particularly from the Unit 42 team, have revealed that Phantom Taurus specializes in the espionage of diplomatic communications and defense data, with a particular emphasis on foreign ministries, embassies, and military operations. The group’s attacks, first documented in June 2023, have been characterized by their stealth, persistence, and ability to quickly adapt to new tactics and techniques.
Phantom Taurus uses custom tools, including a malware suite called NET-STAR, specifically designed to target web servers based on Internet Information Services. This software includes backdoors that allow attackers to maintain access to compromised networks and perform complex operations, such as extracting data from databases using scripts that connect to SQL Server.
The group’s operations suggest a methodological approach, where previous intrusions have exploited known vulnerabilities in local servers and Microsoft Exchange, using methods such as ProxyLogon and ProxyShell to infiltrate target networks. Additionally, the attacks have shown a pattern that coincides with significant global events, indicating a strategic alignment with China’s geopolitical interests.

The sophisticated nature of their attacks and the use of advanced evasion technologies highlight the growing complexity of state-sponsored cyber threats, which poses a considerable challenge for digital security worldwide.