Threats & Adversaries · APT / Espionage
China-Linked Hackers Maintain Years-Long Access to Southeast Asian Militaries Palo Alto Unit 42 attributes a years-long espionage campaign to China-linked CL-STA-1087 that maintained access to Southeast Asian military networks since at least 2020. The group harvested targeted files on military capabilities and C4I and used custom backdoors (AppleChris, MemFun), a Getpass credential stealer, PowerShell, WMI-based lateral movement, and DLL hijacking to persist.
2 sources · Mar 17
Timeline Sources Mar 17 Dark Reading
Chinese Hackers Owned Southeast Asian Military Orgs for Years
Researchers uncovered an extensive cyber espionage campaign that used novel backdoors and familiar evasion techniques to maintain persistent access.
original Mar 16 SecurityWeek
China-Linked Hackers Hit Asian Militaries in Patient Espionage Operation
The state-sponsored hackers deployed custom tools and stayed dormant in the compromised environments for months.
original Part of the PlainSec briefing for 2026-03-17
Every edition of this story: China-Linked Hackers Maintain Years-Long Access to Southeast Asian Militaries
More from today
Threats & Adversaries · APT / Espionage
China-Linked Hackers Maintain Years-Long Access to Southeast Asian Militaries Palo Alto Unit 42 attributes a years-long espionage campaign to China-linked CL-STA-1087 that maintained access to Southeast Asian military networks since at least 2020. The group harvested targeted files on military capabilities and C4I and used custom backdoors (AppleChris, MemFun), a Getpass credential stealer, PowerShell, WMI-based lateral movement, and DLL hijacking to persist.
2 sources · Mar 17
Timeline Sources Mar 17 Dark Reading
Chinese Hackers Owned Southeast Asian Military Orgs for Years
Researchers uncovered an extensive cyber espionage campaign that used novel backdoors and familiar evasion techniques to maintain persistent access.
original Mar 16 SecurityWeek
China-Linked Hackers Hit Asian Militaries in Patient Espionage Operation
The state-sponsored hackers deployed custom tools and stayed dormant in the compromised environments for months.
original Part of the PlainSec briefing for 2026-03-17
Every edition of this story: China-Linked Hackers Maintain Years-Long Access to Southeast Asian Militaries
More from today