Threat reportMalwareTL-2026-0684
HazyBeacon (CL-STA-1020) — AWS Lambda Function URL Abuse for Covert C2 Against Southeast Asian Governments
HazyBeacon (CL-STA-1020) (TL-2026-0684), also tracked as HazyBeacon, is a high-severity malware campaign, first published 2026-06-05. It is attributed to CL-STA-1020 with medium confidence, affects Microsoft Windows, maps to 20 MITRE ATT&CK techniques (T1005, T1041, T1056), and is covered by 9 detection rules and 17 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 20MITRE ATT&CK
- Actors
- 1CL-STA-1020
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 17Indicators of compromise
Key facts for TL-2026-0684
- Threat ID
- TL-2026-0684
- Also known as
- HazyBeacon, CL-STA-1020
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- CL-STA-1020
- Attribution confidence
- MEDIUM
- Motivation
- ESPIONAGE
- Target sectors
- government
- Target regions
- Southeast Asia
- Detection rules
- 9
- Indicators of compromise
- 17
Malware and tooling in HazyBeacon (CL-STA-1020)
Malware and tooling: HazyBeacon
How HazyBeacon (CL-STA-1020) works
CL-STA-1020 is a suspected state-aligned espionage cluster targeting Southeast Asian government entities since late 2024 to collect data on tariffs and trade disputes. It deploys HazyBeacon, a Windows backdoor that abuses AWS Lambda Function URLs (AuthType=NONE) as a covert C2 relay through trusted AWS infrastructure, with Google Drive and Dropbox used for exfiltration.
HazyBeacon is a previously undocumented Windows backdoor used by the suspected state-aligned cluster CL-STA-1020 against government entities across Southeast Asia. The campaign, active since late 2024, focuses on collecting sensitive government documents related to tariffs, trade measures, and disputes — including a targeted search for a 'letter to US President on Tariffs measures.'
The infection chain begins with the malicious DLL mscorsvc.dll planted at C:\Windows\assembly\, which is sideloaded by the legitimate Microsoft binary mscorsvw.exe (the .NET service trigger). Persistence is achieved by registering a Windows service named msdnetsvc that loads the HazyBeacon DLL on reboot. Once running, the backdoor enumerates the host (hostname, IP, user privileges, OS version) and beacons to a threat-actor-controlled AWS Lambda Function URL endpoint in the format <id>.lambda-url.ap-southeast-1.on.aws.
The novel C2 technique abuses AWS Lambda Function URLs configured with AuthType=NONE, exposing an unauthenticated public HTTPS endpoint directly off a Lambda function without API Gateway. Because the traffic terminates on legitimate *.on.aws / amazonaws.com infrastructure — frequently allow-listed due to genuine business dependencies — it blends with normal cloud traffic and evades network-based detection. In broader CL-STA-1020 tradecraft, attackers deploy these relay Lambdas inside victim or third-party AWS accounts using stolen static IAM access keys (harvested from exposed credentials, phishing, or ~/.aws files), validating access with low-noise calls such as 'aws sts get-caller-identity' and 'aws iam list-attached-user-policies' before creating functions (lambda:CreateFunction) and URL configs (lambda:CreateFunctionUrlConfig) under benign names like 'UpdateWorker', often in less-monitored regions. The Lambda strips headers, logs metadata, and transparently proxies encrypted payloads to the attacker's backend, so the issuing infrastructure is never attacker-owned.
Post-exploitation, HazyBeacon downloads a modular toolset to C:\ProgramData\: a file collector (igfx.exe) that searches by timeframe and file extension, a 7-Zip utility (7z.exe) that creates 200MB segmented ZIP archives named after the compromised machine, a Google Drive connector (GoogleGet.exe) accepting drive-ID arguments, multiple custom Google Drive uploaders (google.exe, GoogleDrive.exe, GoogleDriveUpload.exe), and a custom Dropbox uploader (Dropbox.exe). Exfiltration over Google Drive and Dropbox is chosen specifically to blend with sanctioned SaaS traffic. The operators practice cleanup, deleting archives and payloads after exfiltration. Qualys republished an analysis of the campaign on 2026-06-02, reinforcing the original Unit 42 disclosure of 2025-07-14.
MITRE ATT&CK techniques used in TL-2026-0684
Collection
T1005 Data from Local System; T1056 Input Capture; T1560 Archive Collected Data
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Execution
T1059 Command and Scripting Interpreter; T1648 Serverless Execution
Defense Evasion
T1070 Indicator Removal; T1564 Hide Artifacts; T1574 Hijack Execution Flow
Command and Control
T1071 Application Layer Protocol; T1090 Proxy; T1102 Web Service; T1105 Ingress Tool Transfer
Initial Access
Discovery
T1082 System Information Discovery; T1580 Cloud Infrastructure Discovery
Persistence
T1543 Create or Modify System Process; T1547 Boot or Logon Autostart Execution
Credential Access
Affected products and versions in HazyBeacon (CL-STA-1020)
- Microsoft — Windows
Vulnerable versions: Windows endpoints/servers running mscorsvw.exe (.NET) - Amazon Web Services — AWS Lambda Function URLs
Vulnerable versions: Function URLs configured with AuthType=NONE
Remediation for HazyBeacon (CL-STA-1020)
Immediate actions
- Hunt for C:\Windows\assembly\mscorsvc.dll and validate the signature/hash of any mscorsvc.dll loaded by mscorsvw.exe
- Look for a Windows service named msdnetsvc and remove it
- Block/alert on outbound connections to *.lambda-url.*.on.aws from non-developer endpoints
- Hunt for the dropped tools in C:\ProgramData\ (igfx.exe, GoogleGet.exe, google.exe, GoogleDrive.exe, GoogleDriveUpload.exe, Dropbox.exe, 7z.exe)
Workarounds
- Apply Service Control Policies that deny creation of Function URLs with AuthType=NONE unless explicitly tagged/whitelisted
- Set AWS budget/cost alerts for Lambda invocation spikes in non-production regions
Longer-term hardening
- Deploy EDR with behavioral detection for DLL sideloading and unusual service creation
- Enforce egress filtering and SaaS DLP for Google Drive and Dropbox uploads from servers
- Enable AWS CloudTrail across all regions and alert on lambda:CreateFunctionUrlConfig with AuthType=NONE
- Rotate and remove unused static IAM access keys; require MFA
Timeline of HazyBeacon (CL-STA-1020)
- AWS introduces Lambda Function URLs, the feature later abused (with AuthType=NONE) as a covert C2 relay.
- CL-STA-1020 activity begins targeting Southeast Asian government entities to collect data on tariffs and trade disputes.
- Unit 42 (Palo Alto Networks) publicly discloses HazyBeacon and the novel AWS Lambda Function URL C2 abuse; findings shared with Cyber Threat Alliance.
- Qualys republishes a technical analysis of HazyBeacon and the AWS Lambda Function URL command-and-control abuse.
- Threadlinqs Intelligence opens TL-2026-0684 to track HazyBeacon/CL-STA-1020 and build dedicated detection coverage.
Sources cited for HazyBeacon (CL-STA-1020)
- HazyBeacon and AWS Lambda Function URL Abuse | Cloud-Native C2 Explained
- Behind the Clouds: Attackers Targeting Governments in Southeast Asia Implement Novel Covert C2 Communication
- MITRE ATT&CK T1574.002 — DLL Side-Loading
- MITRE ATT&CK T1102 — Web Service
- MITRE ATT&CK T1648 — Serverless Execution
- AWS Lambda Function URLs Documentation
Detection coverage for TL-2026-0684
As of 2026-06-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0684 across Splunk SPL, Microsoft KQL and Sigma, covering 17 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.