Three China-Linked Clusters Target Southeast Asian Government in 2025 Cyber Campaign
ID: fba3ef49-a8ce-52ae-adb3-8c428e6a7b44
STIX ID: report--fba3ef49-a8ce-52ae-adb3-8c428e6a7b44
Feed Name: The Hacker News
Palo Alto Networks Unit 42 observed three China-aligned threat clusters targeting a Southeast Asian government organization during 2025, using USB-delivered HIUPAN/Claimloader, PUBLOAD, the EggStreme framework (EggStremeFuel/Loader), MASOL RAT, TrackBak stealer, Hypnosis Loader with DLL sideloading, and FluffyGh0st RAT to gain and maintain persistent access; activity spans multiple months and overlaps with previously documented groups such as Mustang Panda, Earth Estries/Crimson Palace, and Unfading Sea Haze, indicating coordinated, long-term espionage operations rather than disruptive attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
