logo

Hackers Use USB Malware, RATs, and Stealers in Espionage Attacks on Southeast Asian Government

ID: 2fecd439-ad01-585d-912c-a21a35dcd35e

STIX ID: report--2fecd439-ad01-585d-912c-a21a35dcd35e

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2026-03-27

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A multi-cluster, China-aligned cyberespionage operation targeted a Southeast Asian government (June–August 2025), using a USB worm (USBFect/HIUPAN) to spread the PUBLOAD backdoor, a suite of RATs and an infostealer (TrackBak) in a second cluster, and a stealthy loader (Hypnosis) deploying FluffyGh0st in a third cluster; defenders should note the reported file paths, an EVENT.dll SHA256, and the USB-based propagation and in-memory shellcode techniques used to maintain long-term access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.