Suspected China-Based Espionage Operation Against Military Targets in Southeast Asia
March 16, 2026, 8:28 p.m.
Description
A suspected Chinese state-sponsored espionage campaign targeting Southeast Asian military organizations has been identified, traced back to at least 2020. Designated as CL-STA-1087, the operation demonstrates strategic patience and focused intelligence collection on military capabilities and structures. The attackers deployed custom tools including the AppleChris and MemFun backdoors, and a modified Mimikatz variant called Getpass. The campaign is characterized by the use of dead drop resolvers, custom HTTP verbs, and anti-forensic techniques. Infrastructure analysis reveals long-term persistence and operational compartmentalization. The activity aligns with Chinese working hours and utilizes China-based cloud infrastructure, suggesting a Chinese nexus.
Tags
Date
- Created: March 16, 2026, 10:24 a.m.
- Published: March 16, 2026, 10:24 a.m.
- Modified: March 16, 2026, 8:28 p.m.
Indicators
- 413daa580db74a38397d09979090b291f916f0bb26a68e7e0b03b4390c1b472f
- 9e44a460196cc92fa6c6c8a12d74fb73a55955045733719e3966a7b8ced6c500
- 5a6ba08efcef32f5f38df544c319d1983adc35f3db64f77fa5b51b44d0e5052c
- ee4d4b7340b3fa70387050cd139b43ecc65d0cfd9e3c7dcb94562f5c9c91f58f
- 0e255b4b04f5064ff97da214050da81a823b3d99bce60cdd9ee90d913cc4a952
- ad25b40315dad0bda5916854e1925c1514f8f8b94e4ee09a43375cc1e77422ad
- 2ee667c0ddd4aa341adf8d85b54fbb2fce8cc14aa88967a5cb99babb08a10fae
- 8.212.169.27
- 8.220.184.177
- 116.63.177.49
- 8.220.135.151
- 118.194.238.51
- 154.39.142.177
- 109.248.24.177
- 8.220.177.252
- 154.39.137.203
Additional Informations
- Defense
- Government