China‑Suspected Espionage Targets Southeast Asian Militaries Since 2020

Unit 42 links cluster CL‑STA‑1087, with moderate confidence, to China‑based state actors targeting Southeast Asian militaries. The campaign, active since at least 2020, used custom backdoors AppleChris and MemFun and a Getpass credential harvester to collect narrowly targeted military documents.

Part of the PlainSec briefing for 2026-03-13

Sources