# HazyBeacon (CL-STA-1020) — AWS Lambda Function URL Abuse for Covert C2 Against Southeast Asian Governments

> CL-STA-1020 is a suspected state-aligned espionage cluster targeting Southeast Asian government entities since late 2024 to collect data on tariffs and trade disputes. It deploys HazyBeacon, a Windows backdoor that abuses AWS Lambda Function URLs (AuthType=NONE) as a covert C2 relay through trusted AWS infrastructure, with Google Drive and Dropbox used for exfiltration.

- **Published:** 2026-06-05T00:00:00Z
- **Last reviewed:** 2026-06-05T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0684
- **ID:** TL-2026-0684
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** CL-STA-1020
- **Detections:** 9 · **IOCs:** 17 (full data via the Threadlinqs MCP server — Purple tier)

## Description

HazyBeacon is a previously undocumented Windows backdoor used by the suspected state-aligned cluster CL-STA-1020 against government entities across Southeast Asia. The campaign, active since late 2024, focuses on collecting sensitive government documents related to tariffs, trade measures, and disputes — including a targeted search for a 'letter to US President on Tariffs measures.'

The infection chain begins with the malicious DLL mscorsvc.dll planted at C:\Windows\assembly\, which is sideloaded by the legitimate Microsoft binary mscorsvw.exe (the .NET service trigger). Persistence is achieved by registering a Windows service named msdnetsvc that loads the HazyBeacon DLL on reboot. Once running, the backdoor enumerates the host (hostname, IP, user privileges, OS version) and beacons to a threat-actor-controlled AWS Lambda Function URL endpoint in the format <id>.lambda-url.ap-southeast-1.on.aws.

The novel C2 technique abuses AWS Lambda Function URLs configured with AuthType=NONE, exposing an unauthenticated public HTTPS endpoint directly off a Lambda function without API Gateway. Because the traffic terminates on legitimate *.on.aws / amazonaws.com infrastructure — frequently allow-listed due to genuine business dependencies — it blends with normal cloud traffic and evades network-based detection. In broader CL-STA-1020 tradecraft, attackers deploy these relay Lambdas inside victim or third-party AWS accounts using stolen static IAM access keys (harvested from exposed credentials, phishing, or ~/.aws files), validating access with low-noise calls such as 'aws sts get-caller-identity' and 'aws iam list-attached-user-policies' before creating functions (lambda:CreateFunction) and URL configs (lambda:CreateFunctionUrlConfig) under benign names like 'UpdateWorker', often in less-monitored regions. The Lambda strips headers, logs metadata, and transparently proxies encrypted payloads to the attacker's backend, so the issuing infrastructure is never attacker-owned.

Post-exploitation, HazyBeacon downloads a modular toolset to C:\ProgramData\: a file collector (igfx.exe) that searches by timeframe and file extension, a 7-Zip utility (7z.exe) that creates 200MB segmented ZIP archives named after the compromised machine, a Google Drive connector (GoogleGet.exe) accepting drive-ID arguments, multiple custom Google Drive uploaders (google.exe, GoogleDrive.exe, GoogleDriveUpload.exe), and a custom Dropbox uploader (Dropbox.exe). Exfiltration over Google Drive and Dropbox is chosen specifically to blend with sanctioned SaaS traffic. The operators practice cleanup, deleting archives and payloads after exfiltration. Qualys republished an analysis of the campaign on 2026-06-02, reinforcing the original Unit 42 disclosure of 2025-07-14.

## MITRE ATT&CK

- T1078 Valid Accounts
- T1648 Serverless Execution
- T1059 Command and Scripting Interpreter
- T1543 Create or Modify System Process
- T1547 Boot or Logon Autostart Execution
- T1574 Hijack Execution Flow
- T1564 Hide Artifacts
- T1070 Indicator Removal
- T1552 Unsecured Credentials
- T1082 System Information Discovery
- T1580 Cloud Infrastructure Discovery
- T1005 Data from Local System
- T1560 Archive Collected Data
- T1056 Input Capture
- T1102 Web Service
- T1090 Proxy
- T1071 Application Layer Protocol
- T1105 Ingress Tool Transfer
- T1567 Exfiltration Over Web Service
- T1041 Exfiltration Over C2 Channel

## Sources

- [HazyBeacon and AWS Lambda Function URL Abuse | Cloud-Native C2 Explained](https://blog.qualys.com/qualys-insights/2026/06/02/hazybeacon-aws-lambda-function-url-command-control-abuse)
- [Behind the Clouds: Attackers Targeting Governments in Southeast Asia Implement Novel Covert C2 Communication](https://unit42.paloaltonetworks.com/windows-backdoor-for-novel-c2-communication/)
- [MITRE ATT&CK T1574.002 — DLL Side-Loading](https://attack.mitre.org/techniques/T1574/002/)
- [MITRE ATT&CK T1102 — Web Service](https://attack.mitre.org/techniques/T1102/)
- [MITRE ATT&CK T1648 — Serverless Execution](https://attack.mitre.org/techniques/T1648/)
- [AWS Lambda Function URLs Documentation](https://docs.aws.amazon.com/lambda/latest/dg/urls-auth.html)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0684
