Stealth Cyber Espionage Campaign Targets Southeast Asian Militaries, Linked to Suspected China-Based Actors

Researchers uncovered a coordinated cyber espionage campaign targeting military organizations across Southeast Asia. This activity cluster, which referred to as CL-STA-1087, shows strong indications of being linked to a state-sponsored threat group. Based on behavioral patterns, infrastructure usage, and operational timing, we assess with moderate confidence that the actors behind this campaign are operating from China.

What makes this campaign notable is not just its sophistication, but its patience. Instead of rushing to steal large amounts of data, the attackers carefully selected high-value information. Their focus remained on sensitive military intelligence, including operational capabilities, internal structures, and collaborations with Western defense forces.

The campaign appears to have started as early as 2020 and has continued in a controlled and calculated manner. The attackers relied on custom-built malware, stable infrastructure, and stealthy techniques to maintain long-term access to compromised environments.


Initial Detection and Investigation

The investigation began when newly deployed security agents detected suspicious PowerShell activity inside a targeted network. This activity was not random—it pointed to an already active compromise.

The attackers had established persistence on an unmanaged system within the network. From there, they remotely executed PowerShell scripts across selected machines. These scripts were designed to stay hidden by introducing long delays. For example, they would “sleep” for six hours before initiating any malicious communication.

Once activated, the scripts created reverse connections to command-and-control (C2) servers. These servers acted as the attackers’ remote control points, allowing them to issue commands and receive stolen data.

Interestingly, after setting up persistence, the attackers went quiet for several months. This period of inactivity suggests a deliberate strategy—they were waiting for the right moment to resume operations without drawing attention.


Reactivation and Network Activity

When the attackers resumed activity, multiple alerts were triggered across the network. These alerts revealed a wide range of malicious behavior, including:

  • Communication with external C2 servers
  • Movement across different systems within the network
  • Deployment of additional malware tools
  • Establishment of new persistence mechanisms

This phase marked a shift from silent infiltration to active exploitation.


Lateral Movement and Spread

The attackers began expanding their presence by deploying a custom backdoor known as AppleChris. This malware served as the primary tool for controlling infected systems.

Using legitimate Windows technologies such as Windows Management Instrumentation (WMI) and .NET commands, they spread the malware across multiple endpoints. This approach helped them blend in with normal system activity and avoid detection.

Apple Chris Infection chain, Source : Paloalto

Their targets were not random. They focused on high-value systems, including:

  • Domain controllers
  • Web servers
  • IT administrative workstations
  • Executive-level machines

To maintain persistence, the attackers created malicious services and used DLL hijacking techniques. By placing malicious files in trusted system directories, they ensured their code would run as part of legitimate processes.


Targeted Intelligence Collection

Once they had secured access to critical systems, the attackers shifted their focus to data collection.

Unlike typical cybercriminals who aim for bulk data theft, this group was highly selective. They searched for specific types of documents, including:

  • Official meeting records
  • Joint military operation details
  • Strategic assessments
  • Internal communication related to defense systems

Particular attention was given to C4I systems (Command, Control, Communications, Computers, and Intelligence). This highlights the strategic nature of the campaign, as such information is crucial for military planning and coordination.


Custom Malware Arsenal

During the investigation, three major tools were identified:

1. AppleChris Backdoor

AppleChris is a flexible and evolving backdoor with multiple variants. It uses a technique called Dead Drop Resolver (DDR) to retrieve its C2 server information from public platforms like Pastebin or Dropbox.

This method allows attackers to change their infrastructure without modifying the malware itself, making detection more difficult.

Key features include:

  • File system access (listing, uploading, deleting files)
  • Remote command execution
  • Process monitoring
  • Proxy tunneling capabilities

The malware also uses encryption (RSA and AES) to secure communication with its C2 servers, ensuring that intercepted data remains unreadable.


2. MemFun Backdoor

MemFun is a more advanced, multi-stage malware that operates almost entirely in memory. This reduces its footprint on disk and makes it harder to detect.

Its execution chain involves:

  • A loader that initiates the attack
  • An in-memory downloader
  • A final payload delivered from the C2 server
MemeFun Infection chain, Source : Paloalto

MemFun uses techniques such as:

  • Process hollowing (injecting code into legitimate processes)
  • Reflective DLL loading
  • Anti-forensic measures like timestomping

It also generates unique encryption keys for each session, ensuring secure communication with its operators.


3. Getpass Credential Harvester

The attackers also deployed a modified version of Mimikatz, which we named Getpass.

This tool is designed to extract sensitive credentials directly from system memory. It targets authentication mechanisms such as:

  • Kerberos
  • WDigest
  • NTLM

Unlike standard tools, Getpass runs automatically and stores stolen credentials in a disguised file, making it less noticeable.


Infrastructure and Operational Design

The infrastructure used in this campaign shows a high level of organization and planning.

Evidence suggests that the attackers have been active since at least 2020. Their infrastructure includes:

  • Multiple rotating C2 servers
  • Public platforms (Pastebin, Dropbox) for communication
  • Segmented environments for different targets

This design allows them to scale operations while maintaining resilience against takedowns.


Attribution Indicators

Several factors point toward a Chinese nexus:

  • Activity patterns aligned with UTC+8 working hours
  • Use of China-based hosting infrastructure
  • Simplified Chinese language observed in parts of the infrastructure

While none of these indicators alone are definitive, together they strengthen the attribution assessment.


Conclusion

CL-STA-1087 represents a long-term, highly strategic cyber espionage campaign. The attackers demonstrated patience, technical expertise, and a clear focus on intelligence gathering.

Their use of custom malware, stealth techniques, and adaptable infrastructure highlights the evolving nature of advanced persistent threats (APTs). Organizations, especially those in defense and government sectors, must remain vigilant and adopt proactive security measures to detect and mitigate such threats.


Our Opinion

From an analytical standpoint, this campaign reflects a mature and disciplined approach to cyber espionage. What stands out most is not the complexity of the tools, but the mindset behind their use. The attackers are not relying on noisy or aggressive tactics. Instead, they are operating quietly, maintaining access for extended periods, and extracting only what is necessary.

This level of restraint suggests a clear intelligence objective rather than financial motivation. The focus on military data, especially related to cooperation with Western forces, indicates geopolitical interests. It aligns with broader patterns seen in state-sponsored cyber operations, where the goal is long-term strategic advantage rather than immediate gain.

Another important observation is the balance between custom development and operational security. The attackers created their own malware, such as AppleChris and MemFun, which reduces reliance on publicly known tools. At the same time, they leveraged legitimate platforms like Pastebin and Dropbox, blending malicious activity with normal internet traffic. This combination makes detection significantly more challenging.

The use of techniques like delayed execution, in-memory payloads, and encrypted communication shows a deep understanding of modern defense mechanisms. These are not opportunistic attackers; they are adapting to security technologies and evolving their methods accordingly.

However, one could argue that the campaign also reveals certain limitations. For example, reliance on known platforms like Pastebin introduces potential points of exposure. If defenders monitor these channels effectively, they can disrupt communication between the malware and its operators. Similarly, the reuse of infrastructure over time increases the risk of correlation and attribution.

From a defensive perspective, this case reinforces the importance of visibility and behavioral detection. Traditional signature-based tools are not enough against such threats. Organizations need advanced monitoring solutions that can identify unusual patterns, such as delayed execution scripts or abnormal use of system tools.

In conclusion, CL-STA-1087 is a strong example of how modern cyber espionage operates. It is quiet, persistent, and highly targeted. Defending against such threats requires not only advanced technology but also a proactive and intelligence-driven security strategy.