Espionage hackers aligned with China are targeting foreign ministries, embassies and telcos across Africa, the Middle East, and Asia, researchers have found. Palo Alto Network’s Unit 42 has been observing a previously undocumented nation-state hacking group that it dubbed Phantom Taurus targeting government and telecommunications organizations with the goal of obtaining information connected to geopolitical events and military operations. NET-STAR malwarePhantom Taurus has been seen using operational infrastructure used by other known Chinese groups like APT27, Winnti, and Mustang Panda. They have deployed a mix of commonly used Chinese malware like China Chopper while also using new customized hacking tools the researchers named NET-STAR. One script used for stealing databases was deployed in attacks targeting information on Afghanistan and Pakistan.