China-Linked Hackers Breach Southeast Asian Military Systems in Long-Running Spy Campaign
ID: f07f11b4-d8a2-59f8-9935-b27d4ba7a0ab
STIX ID: report--f07f11b4-d8a2-59f8-9935-b27d4ba7a0ab
Feed Name: cybersecurityNews.com
A persistent, high-sophistication cyber espionage campaign (CL-STA-1087) has targeted Southeast Asian military organizations since at least 2020, using custom backdoors (AppleChris, MemFun) and a modified Mimikatz variant (Getpass) to maintain stealthy long-term access; attackers employed Dead Drop Resolver techniques (Pastebin/Dropbox), memory-resident payloads, DLL hijacking, WMI/PowerShell lateral movement, and focused on C4I systems, with reporting from Unit 42 and PolySwarm linking activity patterns and China-based infrastructure to a China-nexus origin.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
