Hackers Use USB Malware, RATs, and Stealers in Espionage Attacks on Southeast Asian Government
ID: 2fecd439-ad01-585d-912c-a21a35dcd35e
STIX ID: report--2fecd439-ad01-585d-912c-a21a35dcd35e
Feed Name: cybersecurityNews.com
A multi-cluster, China-aligned cyberespionage operation targeted a Southeast Asian government (June–August 2025), using a USB worm (USBFect/HIUPAN) to spread the PUBLOAD backdoor, a suite of RATs and an infostealer (TrackBak) in a second cluster, and a stealthy loader (Hypnosis) deploying FluffyGh0st in a third cluster; defenders should note the reported file paths, an EVENT.dll SHA256, and the USB-based propagation and in-memory shellcode techniques used to maintain long-term access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
