China-Nexus Hackers Skulk in Southeast Asian Military Orgs for Years
ID: 1f376588-cfed-5cf3-a40e-2df5c575bd93
STIX ID: report--1f376588-cfed-5cf3-a40e-2df5c575bd93
Feed Name: Dark Reading
**Executive summary:** Palo Alto Networks Unit 42 uncovered a China-nexus cyberespionage campaign (CL-STA-1087) active since at least 2020 that maintained years-long, stealthy access to Southeast Asian military networks to collect targeted intelligence; attackers used custom backdoors (AppleChris, MemFun), a Getpass credential stealer, dead-drop resolvers hosted on Pastebin and Dropbox, and evasion techniques such as delayed execution and timestomping, and Palo Alto published IOCs including SHA256 hashes and C2 IP addresses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
