Threat Intelligence, Government security, Critical Infrastructure Security

Multi-year China-linked cyberespionage campaign against Southeast Asian militaries uncovered

China Bans Cyber Attacks: Examining Internet Security with Chinese Flag and Binary Data Through a Magnifying Glass Concept

Military organizations across Southeast Asia have been targeted with novel payloads by the suspected Chinese state-backed threat operation CL-STA-1087 as part of a cyberespionage campaign that has been underway since 2020, according to The Hacker News.

CL-STA-1087 has been using an unknown initial attack vector to execute a dubious PowerShell script, which sleeps for six hours before crafting reverse shells to its command-and-control server and spreading two variants of the AppleChris backdoor and the MemFun malware across targeted endpoints to compromise a shared Pastebin account and search for files related to joint military efforts, operational capability evaluations, and official meeting records, a report from Palo Alto Networks Unit 42 researchers revealed. Attacks also involved the deployment of Getpass, a custom iteration of Mimikatz, which facilitates plaintext password, authentication data, and NTLM hash extraction.

"The threat actor behind the cluster demonstrated operational patience and security awareness. They maintained dormant access for months while focusing on precision intelligence collection and implementing robust operational security measures to ensure campaign longevity," said researchers.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds