logo

Three China-Linked Clusters Target Southeast Asian Government in 2025 Cyber Campaign

ID: fba3ef49-a8ce-52ae-adb3-8c428e6a7b44

STIX ID: report--fba3ef49-a8ce-52ae-adb3-8c428e6a7b44

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-03-30

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Palo Alto Networks Unit 42 observed three China-aligned threat clusters targeting a Southeast Asian government organization during 2025, using USB-delivered HIUPAN/Claimloader, PUBLOAD, the EggStreme framework (EggStremeFuel/Loader), MASOL RAT, TrackBak stealer, Hypnosis Loader with DLL sideloading, and FluffyGh0st RAT to gain and maintain persistent access; activity spans multiple months and overlaps with previously documented groups such as Mustang Panda, Earth Estries/Crimson Palace, and Unfading Sea Haze, indicating coordinated, long-term espionage operations rather than disruptive attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.