logo

China-Nexus Hackers Skulk in Southeast Asian Military Orgs for Years

ID: 1f376588-cfed-5cf3-a40e-2df5c575bd93

STIX ID: report--1f376588-cfed-5cf3-a40e-2df5c575bd93

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2026-03-17

Date Updated: 2026-04-21

Author: Rob Wright

...
...

**Executive summary:** Palo Alto Networks Unit 42 uncovered a China-nexus cyberespionage campaign (CL-STA-1087) active since at least 2020 that maintained years-long, stealthy access to Southeast Asian military networks to collect targeted intelligence; attackers used custom backdoors (AppleChris, MemFun), a Getpass credential stealer, dead-drop resolvers hosted on Pastebin and Dropbox, and evasion techniques such as delayed execution and timestomping, and Palo Alto published IOCs including SHA256 hashes and C2 IP addresses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.