HomeSecurityChinese hacking groups targeted Southeast Asian government

Chinese hacking groups target Southeast Asian government

Three Chinese hacking groups have targeted a government agency in Southeast Asiain a complex and well-organized cyberattack described as “sophisticated and resource-rich.” The attacks are part of a broader cyberespionage developed by Chinese threat actors over the course of 2025.

Chinese hacking groups in Southeast Asia

These campaigns led to the development of several malware families, including HIUPAN (also known as USBFect, MISTCLOAK, or U2DiskWatch), PUBLOAD, EggStremeFuel (also known as RawCookie), EggStremeLoader (also known as Gorem RAT), MASOL RAT, PoshRAT, TrackBak Stealer, Hypnosis Loader, and FluffyGh0st. This extensive collection of tools demonstrates the sophisticated nature of the attacks.

See also: Hackers exploit critical RCE flaw in Langflow

The activity has been attributed to three specific groups:

  • From June to August 2025 , the Mustang Panda group (also known as Stately Taurus ) carried out targeted attacks.
  • From March to September 2025 , the group CL-STA-1048 operated , which shares elements with publicly documented groups such as Earth Estries and Crimson Palace .
  • Finally, in April and August 2025 , the CL-STA-1049 group attacked , which has elements in common with the Unfading Sea Haze group .

Techniques and Tools of Chinese Hacking Groups

According to researchers Doel Santos and Hiroaki Hara from Palo Alto Networks Unit 42, these groups exhibit significant overlap in tactics, techniques, and procedures (TTPs) with known Chinese campaigns.

Mustang Panda used the USB-based HIUPAN malware to deliver the PUBLOAD backdoor , via a malicious DLL codenamed Claimloader . The group's first recorded use of Claimloader dates back to late 2022 in attacks against government organizations in the Philippines .

See also: Crunchyroll: Hackers say they stole 100GB of data

Further analysis of the target network revealed the deployment of COOLCLIENT, another known backdoor attributed to Mustang Panda. This tool supports file download/upload, keystroke logging, packet tunneling, and port map information capture.

Chinese hacking groups target Southeast Asian government

The CL-STA-1048 group uses a variety of tools that are characterized as “noisy.” EggStremeFuel is a lightweight backdoor that can download/upload files, list files and directories, start or terminate reverse shells, send the current global IP address , and update the C2 configuration . EggStremeLoader is another component of the EggStreme malware framework that supports 59 backdoor commands for extensive data theft, including a variant that allows file download/upload via Dropbox . MASOL RAT (also known as Backdr-NQ) is a remote access trojan with file download/upload and arbitrary command execution capabilities. Finally, the group uses TrackBak , an information theft program that collects log files, clipboard data, network information, and files from disk drives.

The hacking group CL-STA-1049 uses a DLL loader called Hypnosis Loader, which is launched via DLL side-loading, for the final installation of the FluffyGh0st RAT.

The exact initial access vector used by CL-STA-1048 and CL-STA-1049 remains unclear.

See also: Quest KACE SMA: Hackers exploit critical vulnerability

Chinese hacking groups target Southeast Asian government

Unit 42 researchers emphasize that “ the convergence of these groups, which show connections to known Chinese actors, indicates a coordinated effort to achieve a common strategic goal .” The attackers’ methodology suggests that they intend to gain long-term, persistent access to sensitive government networks, not simply cause disruption. This strategy reflects China ’s broader geopolitical ambitions in the region, according to The HackerNews.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS