Unit 42 found three China-aligned activity clusters targeting a Southeast Asian government in 2025. The clusters operated at overlapping times and deployed multiple distinct malware toolchains to create redundant long-term access. Mustang Panda used a USB-based HIUPAN loader to deliver the PUBLOAD backdoor and maintained a long-running COOLCLIENT implant. Other clusters (CL-STA-1048 and CL-STA-1049) used different backdoors and loaders, complicating detection and remediation.
Part of the PlainSec briefing for 2026-03-31