Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

China-Backed Hackers Target Southeast Asian Military Systems in Ongoing Spy Campaign

China-linked threat actors have been identified targeting Southeast Asian military networks in a cyber espionage campaign focused on intelligence collection and operational surveillance.

China-linked threat actors have been identified targeting Southeast Asian military networks in a cyber espionage campaign focused on intelligence collection and operational surveillance.

The activity, tracked as CL-STA-1087, demonstrates a disciplined approach combining custom malware, stealth techniques, and long-term persistence. The attackers focus on high-value intelligence such as command structures, C4I systems, and joint military operations.

The intrusion was initially detected through suspicious PowerShell activity flagged by endpoint security tools. According to Palo Alto Networks Unit 42, the campaign has been active since at least 2020, primarily targeting military organizations across Southeast Asia. Investigation revealed that attackers had already established persistence within an unmanaged system.

Attackers deployed delayed execution scripts creating reverse shells connecting to multiple command-and-control (C2) servers. These scripts often used six-hour sleep intervals to evade detection. After remaining dormant for months, attackers reactivated access and began lateral movement using Windows Management Instrumentation (WMI) and native .NET tools. Persistence was maintained through service creation and DLL hijacking, including planting malicious libraries in the system32 directory.

The campaign relies heavily on custom-built malware, particularly two backdoors named AppleChris and MemFun.

The activity, tracked as CL-STA-1087, demonstrates a disciplined approach combining custom malware, stealth techniques, and long-term persistence.
Megan Forbes · Thehackingpost

AppleChris: Deployed in multiple variants, it uses a Dead Drop Resolver (DDR) technique to dynamically fetch C2 infrastructure from services like Pastebin and Dropbox. Retrieved data is Base64-decoded and decrypted using an embedded RSA key. It supports file management, process enumeration, and remote command execution via custom HTTP communication. MemFun: Operates entirely in memory and follows a multi-stage infection chain, starting with a loader disguised as a legitimate process. It uses advanced evasion techniques such as timestomping, process hollowing into dllhost.exe, and reflective DLL injection. Communication is encrypted using dynamically generated Blowfish keys.

To escalate access, attackers deployed Getpass, a modified version of Mimikatz. This tool extracts credentials and NTLM hashes directly from the lsass.exe process.

Getpass operates automatically and stores stolen data in a file named WinSAT.db, mimicking a legitimate Windows database to avoid suspicion. The attackers demonstrated strong operational discipline by maintaining long-term access, often pausing activity for extended periods before resuming operations aligned with specific intelligence objectives.

Advertisement

While no specific threat group has been confirmed, several indicators suggest a China-linked origin. These include activity patterns aligned with UTC+8 working hours, use of China-based infrastructure, and Simplified Chinese language artifacts within the environment.

Security analysts assess the campaign as a mature espionage operation designed for stealth and persistence. Its reliance on custom tooling, encrypted communication channels, and in-memory execution reflects a broader trend in advanced threat activity aimed at maintaining prolonged access to sensitive military networks without detection.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories