A cyberespionage operation, allegedly linked to China, has targeted Southeast Asian military organizations (with AppleChris and MemFun) as part of a state-sponsored campaign dating back to at least 2020. Palo Alto Networks Unit 42 is tracking the activity under the name CL-STA-1087.

“The activity demonstrated strategic operational patience and a focus on highly targeted intelligence collection, rather than mass data theft,” security researchers Lior Rochberger and Yoav Zemah.
“The attackers actively sought and collected highly specific records relating to military capabilities, organizational structures, and collaborative efforts with Western armed forces“.
See also: Rust-based VENON malware targets 33 banks
The campaign exhibits characteristics typically associated with advanced persistent threat (APT) operations, including carefully designed delivery methods, defense evasion strategies, highly stable operational infrastructure , and custom payload development designed to support continuous unauthorized access to compromised systems.
AppleChris and MemFun: The “weapons” of CL-STA-1087
The tools used by the attacker include backdoors named AppleChris and MemFun, and a credential harvester called Getpass. The cybersecurity vendor said it detected the attacks after spotting a suspicious PowerShell executionthat allowed the script to enter a sleep state for six hours and then create reverse shells to a command and control (C2) server controlled by the attacker. The exact initial access vector used in the attack remains unknown.
Infection sequence
The infection sequence includes the deployment of AppleChris, different versions of which are installed on targets after lateral movement to maintain persistence and evade signature-based detection. Attackers have also been observed conducting searches related to official meeting records, joint military activitiesMiddle East war: 149 DDoS attacks hit 110 organizations , and detailed assessments of operational capabilities.
“The attackers showed particular interest in files related to military organizational structures and strategy, including command, control, communications, computers, and intelligence (C4I) systems,” the researchers noted.
Both AppleChris and MemFun variants are designed to access a common Pastebin account, which acts as a dead drop resolver to retrieve the actual C2 address stored in Base64-decoded format.
See also: Hive0163 uses AI malware Slopoly in ransomware attacks

A version of AppleChris also relies on Dropbox to information C2 (the Pastebin-based approach is used as a fallback). Pastebin pastes date back to September 2020.
Starting via DLL hijacking, AppleChris initiates contact with the C2 server to receive commands that allow it to perform drive enumeration, directory listing, file upload/download/delete, process counting, remote shell execution, and silent process creation.
The second tunneler represents an evolution of its predecessor, using only Pastebin to obtain the C2 address, in addition to introducing advanced network mediation capabilities. “To bypass automated security systems, some of the malware variants use sandbox evasion tactics during execution,” Unit 42 said.
“These variants enable delayed execution via 30-second (EXE) and 120-second (DLL) sleep timers, effectively bypassing the typical monitoring windows of automated sandboxes“.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
MemFun launched through a multi-stage chain: an initial loader injects shellcode responsible for launching a downloader into memory, whose main purpose is to retrieve C2 configuration details from Pastebin, communicate with the C2 server, and obtain a DLL that, in turn, triggers the execution of the backdoor.
Since the DLL is retrieved by the C2 at runtime, it gives attackers the ability to easily deliver other payloads without having to change anything.
See also: SocksEscort Botnet Dismantled by Law Enforcement Authorities
This behavior turns MemFun into a malware platform with customization capabilities (as opposed to a static backdoor like AppleChris).

MemFun execution begins with a dropper that performs anti-forensic checks before modifying its own file creation timestamp to match the Windows system directory creation time. It then injects the main payload into the memory of a suspended process associated with “dllhost.exe” using a technique referred to as process hollowing.
In this way, the malware runs under the guise of a legitimate Windows process, so that it remains unnoticed and does not leave additional objects on the disk.
The attacks also use a customized version of Mimikatz, known as Getpass, which escalates privileges and attempts to extract plaintext passwords, NTLM hashes, and authentication data directly from the memory of the “lsass.exe” process.
“The threat actor demonstrated operational patience and security awareness,” Unit 42 concluded. “They maintained dormant access for months while focusing on gathering accurate intelligence and implementing robust operational security measures to ensure the longevity of the campaign.”
