Suspected China-Based Espionage Operation Against Military Targets in Southeast Asia

March 16, 2026, 8:28 p.m.

Description

A suspected Chinese state-sponsored espionage campaign targeting Southeast Asian military organizations has been identified, traced back to at least 2020. Designated as CL-STA-1087, the operation demonstrates strategic patience and focused intelligence collection on military capabilities and structures. The attackers deployed custom tools including the AppleChris and MemFun backdoors, and a modified Mimikatz variant called Getpass. The campaign is characterized by the use of dead drop resolvers, custom HTTP verbs, and anti-forensic techniques. Infrastructure analysis reveals long-term persistence and operational compartmentalization. The activity aligns with Chinese working hours and utilizes China-based cloud infrastructure, suggesting a Chinese nexus.

Date

  • Created: March 16, 2026, 10:24 a.m.
  • Published: March 16, 2026, 10:24 a.m.
  • Modified: March 16, 2026, 8:28 p.m.

Indicators

  • 413daa580db74a38397d09979090b291f916f0bb26a68e7e0b03b4390c1b472f
  • 9e44a460196cc92fa6c6c8a12d74fb73a55955045733719e3966a7b8ced6c500
  • 5a6ba08efcef32f5f38df544c319d1983adc35f3db64f77fa5b51b44d0e5052c
  • ee4d4b7340b3fa70387050cd139b43ecc65d0cfd9e3c7dcb94562f5c9c91f58f
  • 0e255b4b04f5064ff97da214050da81a823b3d99bce60cdd9ee90d913cc4a952
  • ad25b40315dad0bda5916854e1925c1514f8f8b94e4ee09a43375cc1e77422ad
  • 2ee667c0ddd4aa341adf8d85b54fbb2fce8cc14aa88967a5cb99babb08a10fae
  • 8.212.169.27
  • 8.220.184.177
  • 116.63.177.49
  • 8.220.135.151
  • 118.194.238.51
  • 154.39.142.177
  • 109.248.24.177
  • 8.220.177.252
  • 154.39.137.203

Attack Patterns

Additional Informations

  • Defense
  • Government

Linked vulnerabilities