CL-STA-0048
CL-STA-0048 is a Chinese state-backed / China-nexus APT cluster tracked by Unit 42 and linked in reporting to Chinese cyber-espionage activity. Content states it has been associated with exploitation of SAP NetWeaver Visual Composer vulnerability CVE-2025-31324 and was previously seen exploiting an Ivanti CSA zero-day. EclecticIQ linked CL-STA-0048 to the SAP activity based on tradecraft overlaps and reported overlap with post-exploitation tactics such as using ping for DNS beaconing and shared infrastructure. Reporting also notes broader industry assessments that UNC5221, UNC5174, and CL-STA-0048 are connected to China’s Ministry of State Security or affiliated private entities. In the SAP NetWeaver intrusions, CL-STA-0048 was one of several Chinese APTs targeting unpatched internet-facing systems. The group was observed issuing thousands of malicious commands to compromised NetWeaver instances for network-level discovery and SAP-specific application mapping, likely to prepare for lateral movement. EclecticIQ reported C2 traffic from compromised systems to 43.247.135[.]53, which resolved to the CL-STA-0048-linked domain sentinelones[.]com over TCP 10443, and observed reverse shell attempts to that host. The activity also included DNS-based beaconing using ping to an oastify.com subdomain shortly after reverse shell execution. The intrusions involved webshell-based post-exploitation and reconnaissance on highly connected SAP environments, including systems connected to internal ICS-adjacent networks. Victimology described in the content includes critical infrastructure and government-related entities in the UK, US, and Saudi Arabia, including natural gas distribution, water and waste utilities, medical device manufacturing, upstream oil and gas, and Saudi government ministries tied to investment and financial regulation. CL-STA-0048 is repeatedly mentioned alongside UNC5221 and UNC5174 as part of the Chinese APT activity exploiting SAP NetWeaver.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
1 malware family attributed to this actor across reporting.
Associated vulnerabilities
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
Observables
11 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
CL-STA-0048 is a Chinese APT group reported to be exploiting SAP NetWeaver CVE-2025-31324, targeting critical infrastructure and enterprise systems.
Chinese APT group conducting reconnaissance and lateral movement preparation in SAP NetWeaver environments.
China-linked activity cluster reported targeting SAP NetWeaver via CVE-2025-31324 exploitation.
China-linked activity cluster reported targeting unpatched SAP NetWeaver instances by exploiting CVE-2025-31324 as part of the broader in-the-wild campaign.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.