logo

Two Chinese APT Groups Ramp Up Cyber Espionage Against ASEAN Countries

ID: 04103c49-bd70-558e-a25c-a4d38c93ec21

STIX ID: report--04103c49-bd70-558e-a25c-a4d38c93ec21

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2024-03-27

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Two China-linked APT clusters (including Mustang Panda) have been observed targeting ASEAN-affiliated entities with spear-phishing and DLL sideloading to deploy PUBLOAD/PlugX and related backdoors, while Trend Micro attributes widespread targeting by a China-focused actor called Earth Krahang that exploits public-facing Openfire/Oracle server flaws and spear-phishing to deliver PlugX, ShadowPad, ReShell, and DinodasRAT. Separately, leaked I-Soon documents reveal an integrated hack-for-hire capability—selling stealers, RATs, and operational platforms and showing operational ties between the contractor and multiple state-aligned groups—illustrating a sophisticated, outsourced Chinese cyber-espionage ecosystem.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.