The images in this article were generated with artificial intelligence. How we publish
A threat investigation team has documented a cyber-espionage operation directed at South-East Asian military organizations, which, according to evidence, dates back to at least 2020. The analysts who sign the report of Unit 42 of Palo Alto Networks They group this activity as CL-STA-1087: a family of intrusions with signs of state sponsorship and a consistent pattern of selective intelligence collection.
What distinguishes this campaign is not the mass of stolen data, but the accuracy with which the attackers sought specific documents.- reports on operational capacities, organizational structures and records of collaborations with Western armies - rather than taking over large volumes of irrelevant information. This deliberate search aims at intelligence purposes that could feed strategic analysis and military planning.

From the technical point of view, the operation shows characteristic features of APT groups: custom-designed payloads, stable control and control infrastructures, defence evasion techniques and execution chains in several phases that facilitate persistent and stealth access to compromised systems. Among the tools identified are the backdoors known as AppleChris and MemFun, and an extractor of credentials named Getpass, a custom variant of the well-known Mimikatz utility ( Mimikatz repository).
One of the interesting operational signs is the use of public services as repositories to hide the actual location of the command and control servers. Both ApplChris and MemFun recover C2 addresses stored in publications of Pastebin (a "dead drop solve" according to MITRE taxonomy), encoded in Base64; a variant even uses Dropbox as a main source and Pastebin only as a backup. These traceable publications date from September 2020, which helps to characterize the longevity of the operation.
The mode of introduction of persistence includes known but still effective techniques to avoid controls: ApplChris can be activated by DLL hijacking, and offers features such as disk exploration, directory listing, file transfer, remote command execution and silent process creation. The evolution of the tunnels in turn shows a greater sophistication in the management of network proxys and in the obtaining of the addresses of C2.
MemFun behaves more like a modular platform: its execution is done through a chain of stages where an initial loader injects shellcode that downloads into memory a component that, in turn, gets the configuration from Pastebin and recovers a DLL from the command server. By bringing the DLL in running time, operators can exchange payloads without touching the initially deployed artifacts, which facilitates modifications and furtive updates.
To avoid being detected by automated analysis environments, some variants implement delays in the execution. They instrumentate sleep timers to exceed the typical sandbox observation windows; in addition, MemFun performs anti-forensic checks before altering time marks and uses process holding to run the payload in the context of legitimate processes such as dllhost.exe, thus reducing the disk footprint and complicating the forensic attribution.
The removal of credentials deserves a separate note: Getpass operates on the memory of lsass.exe to try to obtain passwords in clear text, hashes NTLM and other authentication materials, replicating classic tactics of lateral movements and increased privileges. This capacity makes attackers an even greater threat to networks with low segmentation or weak access control configurations.
What does all this mean for military organizations and entities connected to defence operations? First, the campaign shows that the attackers are selective and patient: they maintain latent access for long periods, prioritize targeted collection and apply operational security measures to prolong their stay. Second, the combined use of modular tools, public services as temporary repositories and avoidance techniques makes the defense more than just antivirus signatures.
From a practical point of view, early detections can be based on the monitoring of suspicious PowerShell executions, the monitoring of processes reading lsass.exe and the identification of connections to pasture or storage services that do not fit the legitimate use pattern. Microsoft offers mechanisms to protect the credentials environment and recommendations to mitigate memory theft; for example, functions such as Creative Guard help reduce the risk of direct extraction from lsass ( Microsoft documentation).

It is also recommended to apply basic but effective hygiene controls: network segmentation, minimum privilege policies, continuous process and outgoing connection performance recording and analysis, and the integration of EDR capabilities that can detect memory injection, process hollowing and abnormal DLL use patterns. To understand the specific techniques used by the attackers it is appropriate to review the techniques mapped by MITRE, which detail vectors such as obtaining C2 via public services and the techniques of hijacking and hollowing already mentioned ( Pastebin, DLL hijacking, process holding).
Attribution to an actor based in China remains in the field of informed suspicion: technical indicators and objectives coincide with previous campaigns associated with state operators, but the security community is often cautious about complete attribution without additional corroboration. What is indisputable is the strategic nature of the objective: command and control systems, organizational structures and military cooperation records are exactly the types of data that interest intelligence services.
In short, we are facing an operation that combines patience, precision and current techniques of evasion. For defenders and security officials in sensitive sectors, the lesson is clear: resilience goes through continuous monitoring, behaviour-based detection and measures to protect credentials and processes. Those who manage critical infrastructure must assume that the trained and state-funded attackers operate on a long time horizon and with very specific objective selection criteria, and prepare their defenses accordingly.
Related
More news on the same subject.

Florida, Iowa, Montana and Nebraska sue TP-Link Systems for security and source of routers
On October 6, four State Attorney General filed complaints against TP- Link Systems in U.S. state courts - in addition to a previous Texas lawsuit - for business practices relat...

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Google reports DNS kidnapping: TLS certificates for google.com.gh, google.sl and google.as
Google reported on October 6 that attackers managed to issue unauthorized HTTPS certificates for Google and YouTube names after compromising authoritative DNS records of three t...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...