A suspected state-sponsored espionage campaign from China targeting military organizations in Southeast Asia with a cloud-native approach.
Analyst brief
CL-STA-1087 is a suspected state-sponsored espionage campaign from China targeting military organizations in Southeast Asia. The threat actor demonstrates operational patience by maintaining long-term dormant access and focusing on precise intelligence collection with robust operational security. Their use of a legitimate cloud service for C2 operations indicates a cloud-native approach. Defenders should closely monitor anomalous network traffic to cloud services, investigate long-standing dormant accounts, and remain vigilant for sensitive data exfiltration on military-affiliated systems.
CL-STA-1087
unknown
CL-STA-1087 is a suspected state-sponsored espionage campaign operating out of China, targeting military organizations in Southeast Asia. The actor has demonstrated operational patience, maintaining dormant access for extended periods while focusing on precision intelligence collection and employing robust operational security measures. Their infrastructure includes the use of a legitimate cloud service for C2 operations, indicating a cloud-native approach. File timestamps and other indicators trace the campaign's activity back to 2020, suggesting a long-running operation.