As part of a state-sponsored campaign that began at least in 2020, a suspected cyber espionage operation based in China has targeted military groups in Southeast Asia.
The threat behavior is being monitored by Palo Alto Networks Unit 42 under the code CL-STA-1087, where CL stands for cluster and STA for state-backed motivation.
According to security researchers Lior Rochberger and Yoav Zemah, the behavior showed strategic operational patience and a focus on highly focused intelligence collection rather than bulk data theft. This cluster’s attackers carefully sought out and gathered extremely specific files about military capabilities, organizational structures, and joint ventures with Western armed forces.
The campaign demonstrates characteristics that are frequently linked to advanced persistent threat (APT) activities, such as carefully considered distribution strategies read more about Chinese Hackers Target Southeast Asian Militaries with AppleChris and MemFun Malware.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
