logo

CL-STA-1087 targets military capabilities since 2020

ID: 9772279b-73bd-5fad-8850-c7c3beb65e46

STIX ID: report--9772279b-73bd-5fad-8850-c7c3beb65e46

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-03-17

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

CL-STA-1087, a suspected China-linked espionage campaign active since 2020, targeted Southeast Asian military organizations using backdoors (AppleChris, MemFun) and a Getpass credential harvester; operators used DLL hijacking, process hollowing/reflective loading, in-memory execution, WMI/.NET persistence, and Pastebin/Dropbox dead-drop resolvers for stealthy, long-term collection of sensitive military and C4I information.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.