China‑linked clusters hit Southeast Asian govt 2025

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Mustang Panda operated from June 1 to August 15 2025, using the USB‑based HIUPAN malware to deliver the PUBLOAD backdoor via a rogue DLL named Claimloader, a technique first seen in 2022 against Philippine government targets.
- Mustang Panda also deployed the COOLCLIENT backdoor, which enables file download/upload, keystroke logging, packet tunneling, and port‑map information capture, indicating a multi‑functional espionage toolkit.
- CL‑STA‑1048 was active March‑September 2025 and employed a suite of “noisy” tools—including EggStremeFuel, EggStremeLoader (with 59 commands and Dropbox file transfer), MASOL RAT, and TrackBak stealer—to exfiltrate data and execute commands.
- CL‑STA‑1049 operated in April and August 2025, using a novel DLL side‑loading loader named Hypnosis Loader to install the FluffyGh0st RAT, though its initial access vector remains unclear.
- Palo Alto Networks Unit 42 researchers linked the three clusters to known China‑aligned actors, noting overlapping tactics, techniques, and procedures that suggest a coordinated campaign aimed at long‑term persistent access to a Southeast Asian government network.
Why it matters: The coordinated Chinese‑aligned clusters give attackers sustained footholds inside a Southeast Asian government network, compromising sensitive data and undermining regional cyber security, while the targeted agency loses operational integrity and faces long‑term espionage risk. The use of multiple malware families and overlapping tactics signals a sophisticated, well‑resourced operation that raises the threat level for neighboring states.
Ask SkimNews



