China-Linked Hackers Maintain Years-Long Access to Southeast Asian Militaries

Palo Alto Unit 42 attributes a years-long espionage campaign to China-linked CL-STA-1087 that maintained access to Southeast Asian military networks since at least 2020. The group harvested targeted files on military capabilities and C4I and used custom backdoors (AppleChris, MemFun), a Getpass credential stealer, PowerShell, WMI-based lateral movement, and DLL hijacking to persist.

Part of the PlainSec briefing for 2026-03-17

Sources