CL-STA-1049
CL-STA-1049 is a China-aligned threat activity cluster that overlaps with the publicly documented group Unfading Sea Haze. In 2025, Unit 42 observed this cluster targeting a government organization in Southeast Asia, with activity in April and August 2025, as part of a broader cyberespionage campaign assessed to be focused on long-term persistent access and data exfiltration from sensitive government networks. CL-STA-1049 used a stealthy, novel DLL loader referred to as Hypnosis Loader (also described as the “Hypnosis” DLL loader) to deploy FluffyGh0st RAT via DLL sideloading, including abuse of a legitimate Bitdefender executable (seccenter.exe). The likely final payload communicated with attacker-controlled command-and-control infrastructure, including webmail.rpcthai[.]com, and FluffyGh0st provided remote control through plugin-based functionality. Reported tradecraft associated with this cluster includes stealth and persistence, multi-payload strategies, and DLL sideloading to maintain access and evade detection. The exact initial access vector for CL-STA-1049 was not identified in the provided content. Known alias in the provided content: CL-STA-1049.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Where they're from
Attributed origin per open-source reporting.
- CN
Tradecraft
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
Observables
34 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with the broader 2025 campaign targeting a Southeast Asian government, using stealthy methods to preserve access and support data theft objectives.
Stealthy espionage cluster using DLL sideloading and a custom loader to deploy FluffyGh0st RAT for persistent remote access and espionage against a Southeast Asian government target.
China-aligned activity cluster targeting a Southeast Asian government organization using a novel DLL loader and RAT to gain long-term persistent access to sensitive government networks.
Stealth-focused espionage cluster using DLL sideloading and a novel loader to deploy FluffyGh0st RAT for persistent remote access against a Southeast Asian government target.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.