Phantom Taurus: A New Chinese Nexus APT and the Discovery of the NET-STAR Malware Suite


Phantom Taurus is a previously undocumented nation-state actor whose espionage operations align with People’s Republic of China (PRC) state interests.

Over the past two and a half years, Unit 42 researchers have observed Phantom Taurus targeting government and telecommunications organizations across Africa, the Middle East, and Asia. Their observations show that Phantom Taurus’ main focus areas include ministries of foreign affairs, embassies, geopolitical events and military operations. The group’s primary objective is espionage.

Read more…
Source: Palo Alto Unit 42


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Two major security flaws are affecting more than six million WordPress websites

    September 7, 2026

    More than six million WordPress users are at risk of website takeover, researchers have claimed after discovering two major vulnerabilities being exploited in the wild. Security researchers Wordfence disclosed finding two flaws, one in Elementor Pro, and one in Super Forms – two popular WordPress plugins. Elementor Pro is a commercial plugin that allows users to build websites using ...

  • More than 1 million users affected in Mathspace data breach across Australia and New Zealand

    September 7, 2026

    More than a million people, including students, school staff, and parents, have been affected following a data breach at Mathspace, according to the learning provider. The company said, in a blog post, “unauthorised parties had accessed an internal reporting system used by Mathspace” and the exposed information included names and email addresses. It said the attackers accessed ...

  • G7 tells businesses to get ready for quantum cybersecurity threats

    September 7, 2026

    The G7, a collection of some of the world’s most powerful economies, is urging organizations to adopt quantum-resistant encryption as soon as possible and minimize the risk of losing sensitive data to technologically advanced threat actors. Virtually every industry in the world today relies on encryption (the process of converting readable data into scrambled, unreadable data ...

  • Dissecting a PHP web server rootkit

    September 7, 2026

    SophosLabs recently acquired a Linux implant associated with compromised BIG-IP Access Policy Management (APM) environments that use Apache and PHP components. The malware demonstrates advanced techniques including custom ELF loading, function hooking, and runtime code patching to evade detection while maintaining persistent access through hidden web shells. The implant delivers a familiar outcome – on-demand server‑side ...

  • Ransomware hackers dump 1.4 million stolen records from German government

    September 7, 2026

    A cybercriminal group known as Rhysida allegedly broke into the network of Berlin’s state government and exfiltrated 1.44 million files. They then tried to extort the government entity for money and when that failed, they leaked it all into the dark web. According to multiple sources, the group first claimed responsibility for the attack on an ...

  • LG TV flaws could let attackers listen in, even in standby mode

    September 7, 2026

    Smart TVs are internet-connected computers with microphones, app stores, advertising systems, and access to the same home networks used by your family’s phones, laptops, printers, and smart-home devices. In the past, we reported on Samsung settling a lawsuit with the Texas Attorney General over how its smart TVs collect and monetize viewing data using Automated Content Recognition (ACR). ACR technology samples what appears ...