Skip to content

Phantom Taurus: New Cyber Espionage Group Targets Governments Worldwide

Meet Phantom Taurus, a stealthy cyber espionage group active since 2022. Its sophisticated tactics and Chinese state-linked targets pose a significant global threat.

there was a room in which people are sitting in the chairs,in front of a table looking into the...
there was a room in which people are sitting in the chairs,in front of a table looking into the laptop and doing something,beside them there are many flee xi in which different advertisements are present which different text.

Phantom Taurus: New Cyber Espionage Group Targets Governments Worldwide

A new cyber espionage group, dubbed Phantom Taurus, has been active since at least 2022. Little is known about the organization behind it, but its operations align with Chinese state interests.

Phantom Taurus focuses on ministries of foreign affairs, embassies, geopolitical events, and military operations. Its targets include government and telecommunications organizations across Africa, the Middle East, and Asia. The group employs unique techniques, tactics, and procedures (TTPs), including the Specter malware family, Ntospy, and NET-STAR. It uses living-off-the-land techniques and an operational infrastructure exclusive to Chinese threat actors. Phantom Taurus has shifted tactics over time, recently targeting SQL Server databases for data theft using a custom batch script (mssq.bat).

The group uses a new, undocumented .NET malware suite called NET-STAR, which comprises three distinct web-based backdoors serving specific roles in the attack chain while maintaining persistence. Phantom Taurus conducts long-term intelligence collection operations to obtain sensitive information.

Phantom Taurus, active since 2022, poses a significant threat to governments and telecommunications organizations worldwide. Despite limited information about its organizational backing, its tactics and targets align with Chinese state interests. Security experts urge vigilance and proactive defense against this evolving cyber espionage group.

Read also:

Latest