Hackers Deploy USB Malware, RATs, and Stealers in Southeast Asian Government Attacks
ID: 2a88c652-3095-5993-9aec-042fe1d153aa
STIX ID: report--2a88c652-3095-5993-9aec-042fe1d153aa
Feed Name: GBHackers
Unit 42 investigated a coordinated, multi-cluster cyberespionage operation targeting a Southeast Asian government from June to August 2025 that used USB-spreading malware (USBFect/HIUPAN) to deploy the PUBLOAD backdoor for lateral movement, while parallel clusters (CL-STA-1048 and CL-STA-1049) deployed loaders, Masol and FluffyGh0st RATs, an infostealer (TrackBak), and DLL sideloading techniques; telemetry, tool overlaps, and victimology link the activity to China-aligned espionage actors and emphasize persistent intelligence collection rather than disruptive actions, with recommended mitigations including USB policy controls, DLL sideloading exposure reviews, and enhanced EDR/XDR detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
