Threats · 182 days ago

China-Linked Hackers Maintain Years-Long Access to Southeast Asian Militaries

Palo Alto Unit 42 attributes a years-long espionage campaign to China-linked CL-STA-1087 that maintained access to Southeast Asian military networks since at least 2020. The group harvested targeted files on military capabilities and C4I and used custom backdoors (AppleChris, MemFun), a Getpass credential stealer, PowerShell, WMI-based lateral movement, and DLL hijacking to persist.

Timeline

Sources

2 sources covering this story

Entities

Part of the PlainSec briefing for 2026-03-17

Editions

Related stories