[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fBnBjCngqHCg9FrRlBA0YKG01EoYCV0RjNDYcqa_aqac":3},{"article":4,"iocs":33,"watch_terms":49},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":18,"category":19,"article_tags":22},"a62fe4df-e9ef-4313-a414-7d92e1854fb6","Three China-Linked Clusters Target Southeast Asian Government in 2025 Cyber Campaign","three-china-linked-clusters-target-southeast-asian-government-in-2025-cyber-camp","Three threat activity clusters aligned with China have targeted a government organization in Southeast Asia as part of what has been described as a \"complex and well-resourced operation.\" The campaigns have led to the deployment of various malware families, including HIUPAN (aka USBFect, MISTCLOAK, or U2DiskWatch), PUBLOAD, EggStremeFuel (aka RawCookie), EggStremeLoader (aka Gorem RAT), MASOL","Three threat activity clusters with suspected Chinese nexus launched a coordinated, well-resourced campaign against a Southeast Asian government organization in 2025. The operation deployed multiple malware families including HIUPAN (USBFect), PUBLOAD, EggStremeFuel (RawCookie), and EggStremeLoader (Gorem RAT). The campaign is characterized as complex and sophisticated, indicating sustained state-sponsored cyber operations in the region.","Three China-linked threat clusters target Southeast Asian government with multiple malware families in 2025.",null,"https:\u002F\u002Fthehackernews.com\u002F2026\u002F03\u002Fthree-china-linked-clusters-target.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEjMVmr08UFvUwMkDRW62724LCJu5Z774vza7r8UADDdCZcBFNJTeJ9WPFkt4BLIknMuCpLYow39D0rgDkTkftiSLBxtPsG3YW6Y7CRiPRxye2Con9Z1lP77VcDv2PA4UJ4PP6nNSCLX0cOKLKJOTCnVerXQ4w5we9s3rMTBbUMMX2hZBB5MLu5t4Ll3YFPe\u002Fs1600\u002Fchinese-hackers.jpg","2026-03-30T07:00:00+00:00","2026-03-30T08:00:13.091241+00:00",8,[],"6cbdd207-aaa1-4176-9534-e156b125e917",{"id":18,"icon":11,"name":20,"slug":21},"Nation-state","nation-state",[23,28],{"category":24},{"id":25,"icon":11,"name":26,"slug":27},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":29},{"id":30,"icon":11,"name":31,"slug":32},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[34,37,40,43,46],{"type":27,"value":35,"context":36},"HIUPAN","Malware variant also known as USBFect, MISTCLOAK, U2DiskWatch deployed in campaign",{"type":27,"value":38,"context":39},"PUBLOAD","Malware family deployed in China-linked Southeast Asia government targeting campaign",{"type":27,"value":41,"context":42},"EggStremeFuel","Malware also tracked as RawCookie, deployed in operation",{"type":27,"value":44,"context":45},"EggStremeLoader","Malware also known as Gorem RAT, deployed in campaign",{"type":27,"value":47,"context":48},"MASOL","Malware family deployed in China-linked operation (details incomplete in source)",[]]