China-Linked Espionage Campaigns Target Regional Government and Military Interests
Security researchers reported multiple China-linked espionage operations, but they are not the same incident. One campaign tracked by Palo Alto Networks as CL-STA-1087 targeted military organizations in Southeast Asia over several years, focusing on intelligence collection related to military capabilities, organizational structures, and cooperation with Western armed forces. The activity used custom malware including the AppleChris and MemFun backdoors and a Getpass credential harvester, alongside stable infrastructure and selective file collection consistent with long-term state-sponsored espionage.
A separate report from Zscaler described a China-nexus intrusion set targeting entities in the Persian Gulf using conflict-themed lures to deliver PlugX. That attack chain relied on a ZIP archive containing a deceptive .lnk file, which downloaded a malicious CHM file, used hh.exe for extraction, displayed a decoy PDF about Iranian missile strikes, and ultimately installed a multi-stage PlugX payload. The other references are unrelated: one is a technical review of CVE-2026-25185 in Windows shortcut handling, and another covers malicious Packagist themes shipping trojanized jQuery tied to FUNNULL infrastructure rather than the China-linked espionage activity described in the relevant reports.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
4 events from the most recent confirmed update back to the earliest known activity.
Unit 42 exposes long-running China-linked military espionage cluster
Unit 42 published research on CL-STA-1087, describing a long-running espionage operation assessed with moderate confidence to be China-based. The report detailed the use of AppleChris, MemFun, and a modified Mimikatz tool called Getpass, along with dead drop resolvers using Pastebin and Dropbox for command-and-control.
ThreatLabz publishes technical analysis of PlugX campaign
Zscaler ThreatLabz disclosed technical details of the March 1, 2026 intrusion chain, including persistence via an HKCU Run key, RC4-encrypted shellcode, inline API hooks, and reflective loading of a PlugX payload with anti-forensics features. The report tied the activity to a China-nexus threat actor targeting the Persian Gulf region.
Threat actor launches PlugX delivery chain against Persian Gulf targets
On March 1, 2026, ThreatLabz observed an attack chain using Middle East conflict-themed lures to target organizations in the Persian Gulf region. The infection began with a ZIP archive containing a disguised LNK that downloaded a malicious CHM and ultimately deployed a PlugX backdoor through DLL sideloading.
CL-STA-1087 begins targeting Southeast Asian military organizations
Unit 42 reported that the espionage cluster tracked as CL-STA-1087 has targeted military organizations in Southeast Asia since at least 2020. The campaign focused on persistent access and collection of sensitive military information, including organizational structures, C4I systems, and cooperation with Western armed forces.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
2 references tracked. Mallory keeps watching after this page renders.
See the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


