logo

China-Backed Hackers Target Southeast Asian Military Systems in Ongoing Spy Campaign

ID: 0d438b26-796d-59e2-bdbe-abfa4599563c

STIX ID: report--0d438b26-796d-59e2-bdbe-abfa4599563c

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-03-25

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

China-linked APT activity (CL-STA-1087) has targeted Southeast Asian military networks since at least 2020 in a long-running espionage campaign focused on high-value intelligence rather than bulk theft. The threat actors use custom backdoors (AppleChris, MemFun) with DDR-based C2 retrieval, in-memory techniques, credential theft via a Mimikatz variant (Getpass), and persistence through service creation and DLL hijacking, enabling stealthy lateral movement across domain controllers, servers, and executive workstations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.