MEDIUMMalware
Global

Three China-Linked Clusters Target Southeast Asian Government in 2025 Cyber Campaign

Monday, March 30, 2026 at 07:00 AM UTC·Source: The Hacker News

Updated: Thursday, April 2, 2026 at 05:46 PM UTC

Executive Summary

Three threat activity clusters aligned with China have targeted a government organization in Southeast Asia as part of what has been described as a "complex and well-resourced operation." The campaigns have led to the deployment of various malware families, including HIUPAN (aka USBFect, MISTCLOAK, or U2DiskWatch), PUBLOAD, EggStremeFuel (aka RawCookie), EggStremeLoader (aka Gorem RAT), MASOL

Analysis

Three threat activity clusters aligned with China have targeted a government organization in Southeast Asia as part of what has been described as a "complex and well-resourced operation." The campaigns have led to the deployment of various malware families, including HIUPAN (aka USBFect, MISTCLOAK, or U2DiskWatch), PUBLOAD, EggStremeFuel (aka RawCookie), EggStremeLoader (aka Gorem RAT), MASOL
Source Attribution

Originally published by The Hacker News on Mar 30, 2026.

Related Threats