China-Aligned Espionage Clusters (Stately Taurus, CL-STA-1048, CL-STA-1049) Deploy USBFect, Masol RAT, FluffyGh0st and Custom Loaders Against Southeast Asian Government
China-Aligned Espionage Clusters (Stately Taurus (TL-2026-0289), also tracked as "[\"Crimson Palace\", is a high-severity advanced persistent threat campaign, first published 2026-03-26. It is attributed to Mustang Panda (China) with high confidence, maps to 28 MITRE ATT&CK techniques (T1005, T1027, T1033), and is covered by 9 detection rules and 65 indicators of compromise.
Key facts for TL-2026-0289
- Threat ID
- TL-2026-0289
- Also known as
- "[\"Crimson Palace\", \"Operation Crimson Palace\", \"Earth Estries Campaign\"]"
- Severity
- HIGH
- Status
- MONITORING
- Category
- APT
- First published
- 2026-03-26
- Last reviewed
- 2026-03-26
- Attribution
- Mustang Panda
- Attribution confidence
- HIGH
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Detection rules
- 9
- Indicators of compromise
- 65
Malware and tooling in China-Aligned Espionage Clusters (Stately Taurus
Malware and tooling: EggStremeFuel, FluffyGh0st, Gorem RAT, Hypnosis Loader, Masol RAT, PUBLOAD - S1228, TrackBak, USBFect
Unit 42 identified three distinct but temporally overlapping China-aligned cyberespionage clusters targeting a Southeast Asian government organization between June-August 2025. The campaigns employed USB-based propagation via USBFect, multiple RATs (PUBLOAD, Masol RAT, FluffyGh0st, Gorem RAT), custom loaders (EggStreme, Hypnosis, ClaimLoader), and infostealers (TrackBak), linked to Stately Taurus, Earth Estries, and Unfading Sea Haze.
How China-Aligned Espionage Clusters (Stately Taurus works
Between June and August 2025, Unit 42 (Palo Alto Networks) observed three distinct but temporally overlapping cyberespionage campaigns targeting the same Southeast Asian government organization. Designated Stately Taurus, CL-STA-1048, and CL-STA-1049, these clusters employed a diverse arsenal of malware families including USBFect (HIUPAN), PUBLOAD, ClaimLoader, CoolClient, EggStreme Loader, EggStremeFuel, Masol RAT, FluffyGh0st, Gorem RAT, Hypnosis Loader, TrackBak, and RawCookie.
**Stately Taurus (June-August 2025):** This cluster leveraged USBFect, a USB-propagating worm that monitors for removable drive insertion and copies itself to attached media. USBFect deployed ClaimLoader (EVENT.dll), which uses XOR decryption and the CryptEnumOIDInfo API to execute PUBLOAD shellcode in memory. PUBLOAD communicates over TCP with fake TLS headers (17 03 03) and XOR-encrypted payloads containing host reconnaissance data. CoolClient, an HP-Socket-based C2 framework supporting file operations, packet tunneling, keylogging, and port mapping, was also deployed on select endpoints with heavy anti-disassembly techniques.
**CL-STA-1048 (August 9, 2025):** This cluster executed a rapid multi-tool deployment within a 40-minute window. EggStremeFuel, a lightweight TCP-based C2 backdoor written in C, was deployed first via Microsoft Edge process injection. It stores RC4-encrypted C2 configurations in Cookies.dat and supports file operations, reverse shell, and configuration updates. Within 20 minutes, Masol RAT was deployed as a Windows service DLL using AES-encrypted HTTP POST C2 communications. Concurrently, EggStreme Loader leveraged DarkLoadLibrary and libpeconv for in-memory loading of Gorem RAT, which uses gRPC for C2 and implements 59 backdoor commands including a user-mode keylogger. TrackBak infostealer followed 40 minutes later, collecting keystrokes, clipboard data, network information, and files from all drives.
**CL-STA-1049 (August 2025):** This cluster exploited Bitdefender's seccenter.exe for DLL side-loading. The novel Hypnosis Loader masquerades as version.dll, proxying all exported functions to the legitimate system DLL while patching the host process entry point to an infinite Sleep function. It then RC4-decrypts the payload filename and loads FluffyGh0st (bdusersy.dll), a custom Gh0st RAT variant that downloads RC4-encrypted and LZNT1-compressed plugins from compromised C2 infrastructure including legitimate Thai company domains.
The convergence of three independent clusters on the same target, with shared Chinese-origin tooling and overlapping TTPs, indicates a coordinated intelligence collection operation. Attribution links to known groups including Earth Estries (Trend Micro), Crimson Palace clusters (Sophos), and Unfading Sea Haze (Bitdefender) suggest a broader state-directed campaign.
MITRE ATT&CK techniques used in TL-2026-0289
collection
T1005 Data from Local System; T1056 Input Capture; T1115 Clipboard Data
defense-evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1055 Process Injection; T1140 Deobfuscate/Decode Files or Information; T1620 Reflective Code Loading
discovery
T1033 System Owner/User Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery
exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
execution
T1059 Command and Scripting Interpreter; T1106 Native API; T1129 Shared Modules
command-and-control
T1071 Application Layer Protocol; T1090 Proxy; T1095 Non-Application Layer Protocol; T1102 Web Service; T1573 Encrypted Channel
lateral-movement
T1091 Replication Through Removable Media; T1570 Lateral Tool Transfer
persistence
T1543 Create or Modify System Process; T1547 Boot or Logon Autostart Execution
stealth
resource-development
T1583 Acquire Infrastructure; T1584 Compromise Infrastructure
Timeline of China-Aligned Espionage Clusters (Stately Taurus
- LAC publishes analysis of ClaimLoader shellcode loader used by Stately Taurus
- Bitdefender publishes Unfading Sea Haze research identifying FluffyGh0st RAT family
- Sophos publishes Operation Crimson Palace analysis with overlapping clusters
- Unit 42 identifies PUBLOAD sample matching configurations used in this campaign
- Stately Taurus PUBLOAD activity begins across multiple endpoints in Southeast Asian government organization via USB-based USBFect propagation
- CL-STA-1049 initiates operations deploying Hypnosis Loader and FluffyGh0st via Bitdefender DLL side-loading
- CoolClient loader DLLs (libvlc.dll, sangforvpnlibcrypto-1_1.dll) detected on endpoints at 08:50:15 UTC as part of Stately Taurus operations
- CL-STA-1048 executes rapid 40-minute multi-tool deployment: EggStremeFuel, Masol RAT, EggStreme Loader (Gorem RAT), and TrackBak infostealer in cascade
- Final observed PUBLOAD propagation at 00:17:15 UTC; Stately Taurus USB-based campaign ceases on monitored endpoints
- Unit 42 publishes comprehensive analysis of three converging espionage clusters targeting the same Southeast Asian government organization
- As of 2026-05-29, the specific SE Asian government intrusion ended on monitored endpoints (last seen Aug 2025), but Stately Taurus/Mustang Panda remains highly active with the same PUBLOAD/HIUPAN/FluffyGh0st tooling and DLL-sideloading TTPs. Darktrace tracked CDN-impersonation campaigns by the actor through April 2026; no takedowns or arrests reported.
Threats related to China-Aligned Espionage Clusters (Stately Taurus
Detection coverage for TL-2026-0289
As of 2026-03-26, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0289 across Splunk SPL, Microsoft KQL and Sigma, covering 65 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.