logo

Chinese Hackers Target Southeast Asian Militaries with AppleChris and MemFun Malware

ID: 9b342e0a-d6ff-5448-89ad-c219fc0600fa

STIX ID: report--9b342e0a-d6ff-5448-89ad-c219fc0600fa

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-03-13

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Palo Alto Networks Unit 42 attributes a long-running, China-linked espionage campaign (CL-STA-1087) targeting Southeast Asian military organizations since at least 2020. The actors used custom backdoors (AppleChris, MemFun), a credential harvester (Getpass/Mimikatz variant), and operational techniques like DLL hijacking, process hollowing, Pastebin/Dropbox-based C2 retrieval, and sandbox-evasion sleep timers to stealthily collect sensitive C4I and joint-military intelligence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.