Suspected China-Based Espionage Operation Against Military Targets in Southeast Asia

robot
Abstract generation in progress

Palo Alto Networks’ Unit 42 identified CL-STA-1087, a suspected China-based espionage operation targeting military organizations in Southeast Asia since at least 2020. This persistent campaign uses custom tools like AppleChris and MemFun backdoors, and a modified Mimikatz variant called Getpass, focusing on collecting specific intelligence on military capabilities and structures. The attackers demonstrate operational patience, utilizing long-term persistence, segmented infrastructure, and evasion techniques such as Dead Drop Resolvers and anti-forensic measures.

This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
0/400
No comments
  • Pin