logo

China-Linked groups target Southeast Asian government with advanced malware in 2025

ID: 59eb705f-3f43-5fa3-b7a8-b5e33ddff73a

STIX ID: report--59eb705f-3f43-5fa3-b7a8-b5e33ddff73a

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-03-30

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

In 2025, multiple China-linked threat clusters conducted a coordinated cyberespionage campaign against a Southeast Asian government, deploying a range of sophisticated malware (including PUBLOAD delivered via USBFect/USBFect, CoolClient loaders, EggStremeFuel, MASOL RAT, TrackBak, Hypnosis Loader and FluffyGh0st) to achieve persistent access, lateral movement, keystroke/clipboard/data theft, and exfiltration; Palo Alto Unit 42 links the activity to known China-aligned actors and highlights extensive tool overlap and stealthy loader techniques used to maintain long-term access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.