logo

Hackers Deploy USB Malware, RATs, and Stealers in Southeast Asian Government Attacks

ID: 2a88c652-3095-5993-9aec-042fe1d153aa

STIX ID: report--2a88c652-3095-5993-9aec-042fe1d153aa

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-03-27

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Unit 42 investigated a coordinated, multi-cluster cyberespionage operation targeting a Southeast Asian government from June to August 2025 that used USB-spreading malware (USBFect/HIUPAN) to deploy the PUBLOAD backdoor for lateral movement, while parallel clusters (CL-STA-1048 and CL-STA-1049) deployed loaders, Masol and FluffyGh0st RATs, an infostealer (TrackBak), and DLL sideloading techniques; telemetry, tool overlaps, and victimology link the activity to China-aligned espionage actors and emphasize persistent intelligence collection rather than disruptive actions, with recommended mitigations including USB policy controls, DLL sideloading exposure reviews, and enhanced EDR/XDR detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.