China-Aligned Espionage Clusters (Stately Taurus, CL-STA-1048, CL-STA-1049) Deploy USBFect, Masol RAT, FluffyGh0st and Custom Loaders Against Southeast Asian Government — Threadlinqs Intelligence
As of 2026-05-30, China-Aligned Espionage Clusters (Stately Taurus, CL-STA-1048, CL-STA-1049) Deploy USBFect, Masol RAT, FluffyGh0st and Custom Loaders Against Southeast Asian Government is a high-severity apt threat attributed to Mustang Panda (China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 65 indicators of compromise.
Threat ID: TL-2026-0289 · Severity: HIGH · Status: MONITORING · Category: APT
Attribution: Mustang Panda · China · ESPIONAGE
Unit 42 identified three distinct but temporally overlapping China-aligned cyberespionage clusters targeting a Southeast Asian government organization between June-August 2025. The campaigns employed
Between June and August 2025, Unit 42 (Palo Alto Networks) observed three distinct but temporally overlapping cyberespionage campaigns targeting the same Southeast Asian government organization. Designated Stately Taurus, CL-STA-1048, and CL-STA-1049, these clusters employed a diverse arsenal of malware families including USBFect (HIUPAN), PUBLOAD, ClaimLoader, CoolClient, EggStreme Loader, EggStremeFuel, Masol RAT, FluffyGh0st, Gorem RAT, Hypnosis Loader, TrackBak, and RawCookie.
**Stately Taurus (June-August 2025):** This cluster leveraged USBFect, a USB-propagating worm that monitors for removable drive insertion and copies itself to attached media. USBFect deployed ClaimLoader (EVENT.dll), which uses XOR decryption and the CryptEnumOIDInfo API to execute PUBLOAD shellcode in memory. PUBLOAD communicates over TCP with fake TLS headers (17 03 03) and XOR-encrypted payloads containing host reconnaissance data. CoolClient, an HP-Socket-based C2 framework supporting file operations, packet tunneling, keylogging, and port mapping, was also deployed on select endpoints with heavy anti-disassembly techniques.
**CL-STA-1048 (August 9, 2025):** This cluster executed a rapid multi-tool deployment within a 40-minute window. EggStremeFuel, a lightweight TCP-based C2 backdoor written in C, was deployed first via Microsoft Edge process injection. It stores RC4-encrypted C2 configurations in Cookies.dat and supports file operations, reverse shell, and configuration updates. Within 20 minutes, Masol RAT was deployed as a Windows service DLL using AES-encrypted HTTP POST C2 communications. Concurrently, EggStreme Loader leveraged DarkLoadLibrary and libpeconv for in-memory loading of Gorem RAT, which uses gRPC for C2 and implements 59 backdoor commands including a user-mode keylogger. TrackBak infostealer followed 40 minutes later, collecting keystrokes, clipboard data, network information, and files from all drives.
**CL-STA-1049 (August 2025):** This cluster exploited Bitdefender's seccenter.exe for DLL side-loading. The novel Hypnosis Loader masquerades as version.dll, proxying all exported functions to the legitimate system DLL while patching the host process entry point to an infinite Sleep function. It then RC4-decrypts the payload filename and loads FluffyGh0st (bdusersy.dll), a custom Gh0st RAT variant that downloads RC4-encrypted and LZNT1-compressed plugins from compromised C2 infrastructure including legitimate Thai company domains.
The convergence of three independent clusters on the same target, with shared Chinese-origin tooling and overlapping TTPs, indicates a coordinated intelligence collection operation. Attribution links to known groups including Earth Estries (Trend Micro), Crimson Palace clusters (Sophos), and Unfading Sea Haze (Bitdefender) suggest a broader state-directed campaign.
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 65 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, HIGH, threat intelligence, cybersecurity, T1091, T1106, T1059, T1129, T1547, T1543, T1574, T1574, T1055, T1574