Research Saturday
Research Saturday
N2K Networks
China’s stealthiest spy operation yet.
22 minutes Posted Oct 4, 2025 at 5:00 am.
0:00
22:52
Download MP3
Show notes
Assaf Dahan, Director of Threat Research, Cortex XDR, at Palo Alto Networks, discussing Phantom Taurus, a new China APT uncovered by Unit 42. Unit 42 researchers have identified Phantom Taurus, a newly designated Chinese state-aligned APT conducting long-term espionage against government and telecommunications organizations across Africa, the Middle East, and Asia.
Distinguished by its stealth, persistence, and rare tactics, the group has recently shifted from email-focused data theft to directly targeting databases and deploying a powerful new malware suite called NET-STAR, designed to compromise IIS web servers and evade detection. This suite, featuring modular, fileless backdoors and advanced evasion capabilities, marks a significant evolution in Phantom Taurus’ operations and underscores the group’s strategic intelligence-gathering objectives.
The research can be found here:
⁠Phantom Taurus: A New Chinese Nexus APT and the Discovery of the NET-STAR Malware Suite