INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

China-Linked Groups Target Southeast Asian Government with Advanced Malware

| 2026-03-30 18:05 CRITICAL HIGH
Executive Summary AI-generated
The threat landscape is increasingly dominated by China-linked groups, with a focus on sophisticated cyber campaigns that exploit advanced malware families. These groups have been linked to multiple attacks across Southeast Asia in 2025 and earlier years, including the targeting of governments with PUBLOAD malware and the deployment of complex, well-funded operations. The use of tactics such as tooling and methods links these groups to China-affiliated activity, highlighting a potential coordination between them.
Technical Mitigations AI-generated
* Use of secure boot and UEFI firmware: Ensure that the system's UEFI firmware is set to use secure boot, which can help prevent malware from loading during startup. * Regularly update operating systems and software: Keep the operating system and all software up-to-date with the latest security patches and updates to ensure that any known vulnerabilities are addressed. * Implement a firewall and intrusion detection/prevention (IDP) system: Configure a firewall and IDP system to detect and block suspicious activity, such as unusual network traffic or unauthorized access attempts. * Use antivirus software and keep it up-to-date: Install and regularly update antivirus software that is specifically designed for your operating system and has been tested against known malware threats.
Technical Observables
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence distributed on:
Incident Link
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Salt TyphoonSalt TyphoonMustang PandaMustang Panda HIUPANHIUPANCrimsonCrimsonPUBLOADPUBLOAD
Target & Sectors
APAC APAC
Incident Timeline
June 1, 2025
USBFect is a worm that spreads via removable media, often used to propagate PUBLOAD for lateral movement and automatically installs malicious components.
attribution Stately Taurus
malware PUBLOAD
source_region APAC
organisation EVENT.dll
organisation USBfect
organisation ClaimLoader
organisation USB
August 15, 2025
Threat actors used a newly discovered advanced malware to target government entities in Southeast Asia.
August 2025
China-linked groups used PUBLOAD malware propagated via USBFect-infected drives to target a Southeast Asian government in 2025.
threat_actor Mustang Panda
malware Crimson
threat_actor Salt Typhoon
organisation CL-STA-1049
organisation SecurityAffairs
organisation CoolClient
organisation HP-Socket
organisation Stately Taurus
organisation EggStreme Loader
organisation TrackBak
organisation EggStreme
organisation Palo alto Networks
organisation Cluster CL-STA-1049
organisation DLL
organisation CL-STA-1048’s
organisation CL-STA-1049’s
mid-August 2025
PUBLOAD exploited a vulnerability in TCP to exfiltrate sensitive data from targeted government entities.
malware PUBLOAD
organisation TCP
September 2025
Threat actors used a cluster of advanced malware, CL-STA-1049, to target the Unfading Sea Haze government in Southeast Asia.
threat_actor Mustang Panda
malware Crimson
threat_actor Salt Typhoon
organisation CL-STA-1049
Mar 30, 2026
Threat actors used a newly discovered advanced malware to target government entities in Southeast Asia.
30, 2026
Threat actors used China's advanced malware to target a government organization in Southeast Asia.
target_region China
target_region APAC
attribution Threat Intelligence / Network Intrusion
June - August 2025
Threat actors used a custom-built, zero-day exploit to target the government of Southeast Asia in June-August 2025.
threat_actor Mustang Panda
organisation Stately Taurus
March - September 2025
Threat actors used CL-STA-1048, an advanced malware, to target government entities in Southeast Asia.
malware Crimson
organisation Earth Estries
April and August 2025 - CL-STA-1049
Threat actors used a newly discovered advanced malware, CL-STA-1049, to target government entities in Southeast Asia.
between June 1 and August 15, 2025
Threat actors used a USB-based malware known as HIUPAN to deliver the PUBLOAD backdoor by means of a rogue DLL codenamed Claimloader.
threat_actor Mustang Panda
malware PUBLOAD
malware HIUPAN
organisation USB
organisation DLL
organisation Infection
2026-03-30
China-Linked groups deployed advanced malware targeting a Southeast Asian government in 2025.
threat_actor Mustang Panda
organisation CoolClient
organisation Hypnosis Loader
organisation MISTCLOAK
organisation U2DiskWatch
organisation RawCookie
organisation TrackBak
organisation EggStreme
organisation IP
organisation Palo Alto Networks Unit
organisation CL-STA-1049
organisation MASOL
organisation Backdr-NQ