Threats · 182 days ago
Palo Alto Unit 42 attributes a years-long espionage campaign to China-linked CL-STA-1087 that maintained access to Southeast Asian military networks since at least 2020. The group harvested targeted files on military capabilities and C4I and used custom backdoors (AppleChris, MemFun), a Getpass credential stealer, PowerShell, WMI-based lateral movement, and DLL hijacking to persist.
2 sources covering this story
Chinese Hackers Owned Southeast Asian Military Orgs for Years
Researchers uncovered an extensive cyber espionage campaign that used novel backdoors and familiar evasion techniques to maintain persistent access.
China-Linked Hackers Hit Asian Militaries in Patient Espionage Operation
The state-sponsored hackers deployed custom tools and stayed dormant in the compromised environments for months.
Part of the PlainSec briefing for 2026-03-17