CL-STA-1087 targets military capabilities since 2020
ID: 9772279b-73bd-5fad-8850-c7c3beb65e46
STIX ID: report--9772279b-73bd-5fad-8850-c7c3beb65e46
Feed Name: Security Affairs
Threat Score
CL-STA-1087, a suspected China-linked espionage campaign active since 2020, targeted Southeast Asian military organizations using backdoors (AppleChris, MemFun) and a Getpass credential harvester; operators used DLL hijacking, process hollowing/reflective loading, in-memory execution, WMI/.NET persistence, and Pastebin/Dropbox dead-drop resolvers for stealthy, long-term collection of sensitive military and C4I information.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
