Threats & Adversaries · APT / Espionage

China-Linked Hackers Maintain Years-Long Access to Southeast Asian Militaries

Palo Alto Unit 42 attributes a years-long espionage campaign to China-linked CL-STA-1087 that maintained access to Southeast Asian military networks since at least 2020. The group harvested targeted files on military capabilities and C4I and used custom backdoors (AppleChris, MemFun), a Getpass credential stealer, PowerShell, WMI-based lateral movement, and DLL hijacking to persist.

2 sources · Mar 17

Timeline

Sources

Part of the PlainSec briefing for 2026-03-17

Every edition of this story: China-Linked Hackers Maintain Years-Long Access to Southeast Asian Militaries

More from today