China-Backed Hackers Target Southeast Asian Military Systems in Ongoing Spy Campaign
ID: 0d438b26-796d-59e2-bdbe-abfa4599563c
STIX ID: report--0d438b26-796d-59e2-bdbe-abfa4599563c
Feed Name: GBHackers
China-linked APT activity (CL-STA-1087) has targeted Southeast Asian military networks since at least 2020 in a long-running espionage campaign focused on high-value intelligence rather than bulk theft. The threat actors use custom backdoors (AppleChris, MemFun) with DDR-based C2 retrieval, in-memory techniques, credential theft via a Mimikatz variant (Getpass), and persistence through service creation and DLL hijacking, enabling stealthy lateral movement across domain controllers, servers, and executive workstations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
