logo

China-Linked Hackers Breach Southeast Asian Military Systems in Long-Running Spy Campaign

ID: f07f11b4-d8a2-59f8-9935-b27d4ba7a0ab

STIX ID: report--f07f11b4-d8a2-59f8-9935-b27d4ba7a0ab

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-03-25

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A persistent, high-sophistication cyber espionage campaign (CL-STA-1087) has targeted Southeast Asian military organizations since at least 2020, using custom backdoors (AppleChris, MemFun) and a modified Mimikatz variant (Getpass) to maintain stealthy long-term access; attackers employed Dead Drop Resolver techniques (Pastebin/Dropbox), memory-resident payloads, DLL hijacking, WMI/PowerShell lateral movement, and focused on C4I systems, with reporting from Unit 42 and PolySwarm linking activity patterns and China-based infrastructure to a China-nexus origin.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.