Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
state-sponsored-espionagegovernment-diplomatic-threatremote-access-implantcredential-access-method

China-Linked Espionage Campaigns Target Regional Government and Military Interests

Updated 3mo agoFirst seen Mar 13, 20262 sources

Security researchers reported multiple China-linked espionage operations, but they are not the same incident. One campaign tracked by Palo Alto Networks as CL-STA-1087 targeted military organizations in Southeast Asia over several years, focusing on intelligence collection related to military capabilities, organizational structures, and cooperation with Western armed forces. The activity used custom malware including the AppleChris and MemFun backdoors and a Getpass credential harvester, alongside stable infrastructure and selective file collection consistent with long-term state-sponsored espionage.

A separate report from Zscaler described a China-nexus intrusion set targeting entities in the Persian Gulf using conflict-themed lures to deliver PlugX. That attack chain relied on a ZIP archive containing a deceptive .lnk file, which downloaded a malicious CHM file, used hh.exe for extraction, displayed a decoy PDF about Iranian missile strikes, and ultimately installed a multi-stage PlugX payload. The other references are unrelated: one is a technical review of CVE-2026-25185 in Windows shortcut handling, and another covers malicious Packagist themes shipping trojanized jQuery tied to FUNNULL infrastructure rather than the China-linked espionage activity described in the relevant reports.

Share:
China-Linked Espionage Campaigns Target Regional Government and Military Interests
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Mar 12, 20263mo ago

Unit 42 exposes long-running China-linked military espionage cluster

Unit 42 published research on CL-STA-1087, describing a long-running espionage operation assessed with moderate confidence to be China-based. The report detailed the use of AppleChris, MemFun, and a modified Mimikatz tool called Getpass, along with dead drop resolvers using Pastebin and Dropbox for command-and-control.

ThreatLabz publishes technical analysis of PlugX campaign

Zscaler ThreatLabz disclosed technical details of the March 1, 2026 intrusion chain, including persistence via an HKCU Run key, RC4-encrypted shellcode, inline API hooks, and reflective loading of a PlugX payload with anti-forensics features. The report tied the activity to a China-nexus threat actor targeting the Persian Gulf region.

Mar 1, 20264mo ago

Threat actor launches PlugX delivery chain against Persian Gulf targets

On March 1, 2026, ThreatLabz observed an attack chain using Middle East conflict-themed lures to target organizations in the Persian Gulf region. The infection began with a ZIP archive containing a disguised LNK that downloaded a malicious CHM and ultimately deployed a PlugX backdoor through DLL sideloading.

Jan 1, 20206y ago

CL-STA-1087 begins targeting Southeast Asian military organizations

Unit 42 reported that the espionage cluster tracked as CL-STA-1087 has targeted military organizations in Southeast Asia since at least 2020. The campaign focused on persistent access and collection of sensitive military information, including organizational structures, C4I systems, and cooperation with Western armed forces.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

18 LINKEDOpen in app
Affected products
6 linked
NetPowershellInternet ExplorerDropboxIda ProWindows
Organizations
7 linked
Palo Alto NetworksDropboxMicrosoft CorporationPastebinZscalerBitdefenderGoogle
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.