Threats · 186 days ago
Unit 42 links cluster CL‑STA‑1087, with moderate confidence, to China‑based state actors targeting Southeast Asian militaries. The campaign, active since at least 2020, used custom backdoors AppleChris and MemFun and a Getpass credential harvester to collect narrowly targeted military documents.
1 source covering this story
Suspected China-Based Espionage Operation Against Military Targets in Southeast Asia
An espionage operation demonstrated strategic operational patience against targets in Southeast Asia, deploying custom backdoors.
Part of the PlainSec briefing for 2026-03-13