The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Chinese-linked cyber-espionage groups maintained access to some Southeast Asian military and government networks for years, but the public evidence does not prove one uninterrupted operation or identify a specific Chinese ministry. Palo Alto Networks Unit 42 traced the cluster it calls CL-STA-1087 to at least 2020 and assessed, with moderate confidence, that it operated from China. Its operators searched selectively for military planning, force structures, cooperation records and C4I information rather than stealing data indiscriminately.
Separate reporting describes Sophos’s nearly two-year Operation Crimson Palace against a high-level Southeast Asian government organization, Microsoft activity around South China Sea exercises, and a Cyber Security Agency of Singapore (CSA) campaign from October 2023 through January 2024. Together, these cases show persistent regional espionage, not a single publicly proven campaign.
How long were the intruders inside?
The clearest minimum comes from Unit 42: CL-STA-1087 activity dates back to at least 2020. That is a lower bound for the activity Unit 42 attributed to this cluster, not proof that every related intrusion began then or that access was continuous.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteSophos separately described Operation Crimson Palace as a nearly two-year campaign. Its follow-up reporting said one cluster later reached at least 11 additional organizations and agencies in the region; that is the vendor’s reported count, not a complete list of victims. Sophos also said one cluster remained active through at least April 2024.
#1 Best Overall
- Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
- Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
- High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
- Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
- Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
Microsoft documented China-based actors targeting regional military, maritime, government and telecommunications entities around South China Sea exercises. CSA reported a TAG-43 campaign compromising ASEAN organizations and media through edge devices between October 2023 and January 2024. These dates overlap, but public reporting does not establish that they are phases of one operation.
What the public record actually attributes
Unit 42: CL-STA-1087
Unit 42 identified a cluster targeting Southeast Asian military organizations and said it was “suspected with moderate confidence to be operating out of China.” The report describes “strategic operational patience” and “highly targeted intelligence collection, rather than bulk data theft.” The designation CL-STA-1087 is Unit 42’s label; it is not a confirmed government identity.
Sophos: Operation Crimson Palace
Sophos found three overlapping activity clusters against a high-level Southeast Asian government organization. It reported overlaps with BackdoorDiplomacy, APT15 and Earth Longzhi, which Sophos describes as a reported APT41 subgroup. Sophos director Paul Jaramillo said the clusters appeared to be working in support of Chinese state interests by collecting military and economic intelligence related to South China Sea strategies. That wording expresses an assessment, not proof that a named Chinese agency directed the intrusions.
Microsoft and CSA observations
Microsoft’s reporting connected China-based activity to ASEAN military, maritime, government and telecommunications targets and to exercises involving Indonesia, China, the United States and regional partners. In June 2023, Microsoft said Raspberry Typhoon targeted Indonesian military and executive entities and a Malaysian maritime system before a multilateral naval exercise. CSA’s regional threat reporting says advanced persistent threats primarily target governments and critical infrastructure for espionage.
Rank #2
- HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
- UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
- OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
- RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
- EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.
Which organizations and systems were targeted?
The available reports identify victim categories and examples rather than a definitive roster of every Southeast Asian military. Observed targets included:
- Southeast Asian military organizations and defense-related government bodies.
- Indonesian military and executive entities, according to Microsoft’s Raspberry Typhoon reporting.
- A Malaysian maritime system targeted before a multilateral naval exercise.
- High-level government organizations and at least 11 additional regional organizations or agencies reported by Sophos.
- Government, telecommunications and other ASEAN entities compromised through exposed edge devices in the CSA-described TAG-43 campaign.
Unit 42 said operators reached domain controllers, web servers, IT workstations and executive assets. That spread gives an attacker multiple routes to authenticate, locate sensitive files and maintain access even if one endpoint is cleaned.
What information were they looking for?
Unit 42 observed searches for:
- Official meeting records and records of joint military activities.
- Detailed assessments of operational capabilities.
- Organizational structures and force relationships.
- C4I systems—command, control, communications, computers and intelligence.
Sophos reported collection of political, economic and military information, along with credentials and authentication tokens. The pattern supports an intelligence-preparation objective: mapping forces, plans, communications and cooperation so that later decisions can be made with better information. That is an analytic interpretation of the observed searches and exercise-linked targeting, not a disclosed statement of intent from the operators.
Campaigns compared
| Case | Victims and geography | Observed duration or tempo | Collection focus | Attribution language | Last public status |
|---|---|---|---|---|---|
| CL-STA-1087 (Unit 42) | Southeast Asian military organizations | Activity traced to at least 2020; patient, selective operations | Meetings, joint activities, capabilities, structures and C4I | Suspected China-based, moderate confidence | Unit 42’s report establishes the historical activity; it does not make a current-activity claim |
| Operation Crimson Palace (Sophos) | High-level Southeast Asian government organization and later at least 11 additional regional organizations or agencies | Nearly two years | Political, economic and military information, credentials and tokens | Three clusters with overlaps reported with BackdoorDiplomacy, APT15 and Earth Longzhi | One cluster active through at least April 2024 |
| Raspberry Typhoon (Microsoft) | Indonesian military and executive entities; Malaysian maritime system | Observed around a June 2023 multilateral naval exercise | Regional military and maritime intelligence | China-based actor identified by Microsoft | Report covers the exercise-linked activity; it does not establish continuing access |
| TAG-43 (CSA) | ASEAN organizations and media | October 2023–January 2024 | Espionage via compromised edge devices | CSA campaign designation; public summary does not name a definitive Chinese ministry | Campaign period reported by CSA |
What malware and techniques were used?
CL-STA-1087 tooling
Unit 42 identified the AppleChris and MemFun backdoors and a custom Getpass credential harvester. AppleChris variants used persistence services, DLL hijacking, PowerShell and lateral movement. AppleChris and MemFun also used custom HTTP verbs and a dead-drop resolver tied to a shared Pastebin account. A dead-drop resolver lets malware retrieve changing command-and-control details from an otherwise ordinary public service, making simple domain blocking less reliable.
Rank #3
- 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
- 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
- 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
- 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
- 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles
Crimson Palace tooling
Sophos documented PocoProxy, which masqueraded as a Microsoft executable, as well as CCoreDoor and upgraded EAGERBEE across the three clusters. Cluster Charlie exfiltrated military and political documents plus credentials and tokens and remained active at least through April 2024.
The combination of forged or misleading filenames, hijacked DLL loading, new services, PowerShell and credential theft is designed to blend into normal administration. Long dwell time also allows operators to remove noisy tools, change infrastructure and return only when useful intelligence appears.
Was this the Chinese military or an intelligence service?
Public reporting does not establish that the People’s Liberation Army, China’s Ministry of State Security or another named ministry directly ran CL-STA-1087. The defensible descriptions are “China-linked,” “suspected China-based” and, where a source uses that wording, “Chinese state-sponsored activity.”
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Sophos’s assessment that clusters worked in support of Chinese state interests and Microsoft’s China-based actor descriptions indicate strategic alignment, but they are not equivalent to a government identity backed by public evidence. Different campaigns may involve different operators, contractors or intelligence requirements.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Why the activity matters
Military meeting records, exercise schedules, force structures and C4I details can reveal how countries cooperate, where capabilities are concentrated and which communications or command relationships matter during a crisis. Exercise-linked targeting is especially significant because it can expose plans and procedures involving several countries, including the United States and South China Sea partners.
Rank #4
- Runs UniFi Network for full-stack network management
- Manages 30+ UniFi Network devices and 300+ clients
- 1 Gbps routing with IDS/IPS
- Multi-WAN load balancing
- 0.96" LCM status display
These operations also demonstrate why a network can be “owned” without constant visible activity. An adversary may keep credentials and persistence dormant, wake a foothold for a narrow search, then disappear again. A low-volume intrusion can therefore have high strategic value while producing less evidence than bulk ransomware or mass data theft.
How defense organizations can hunt for a dormant foothold
Start with identity and endpoint inventory
- Find dormant, newly enabled or rarely used privileged accounts, service accounts and tokens.
- Reconcile every domain controller, web server, executive workstation and unmanaged endpoint with an owner and approved software baseline.
- Rotate credentials and revoke tokens after investigating suspicious access; do not assume that deleting one malware file removes stolen authentication material.
Review execution and persistence telemetry
- Search for unusual PowerShell, newly created services and DLL hijacking, especially when the parent process, path or signer is inconsistent with the installed application.
- Alert on executables that imitate Microsoft names or appear in unexpected directories, including PocoProxy-like masquerading.
- Correlate endpoint events with lateral movement, domain-controller access and use of executive or administrative accounts.
Inspect network and DNS behavior
- Look for custom HTTP verbs and outbound requests to paste or other public services that could serve as dead-drop resolvers.
- Review DNS and cloud-traffic logs for command-and-control infrastructure hosted in China or infrastructure that changes shortly after a public-service lookup.
- Hunt for low-frequency beaconing and short, selective transfers rather than relying only on high-volume exfiltration alerts.
Search for the intelligence objective
- Audit access to meeting minutes, exercise plans, capability assessments, organization charts and C4I documentation.
- Identify unusual bulk searches or staged archives involving military and political file shares, even when the total data volume is small.
- Compare access times with exercises, ministerial meetings and other events; a dormant actor may become visible only when an operation is preparing for a specific event.
Coordinate response across agencies
CSA emphasizes coordinated protection of critical infrastructure and exercises involving government, sector leads and the Singapore Armed Forces’ Digital and Intelligence Service. Defense organizations should share indicators across military, government, telecommunications and maritime networks, preserve forensic images before rebuilding systems, and run exercises that test both technical containment and classified-information handling.
Palo Alto Networks identifies Advanced WildFire, Advanced URL Filtering, Advanced DNS Security, Cortex XDR and XSIAM as protections relevant to the behaviors in its CL-STA-1087 reporting. Those product references do not replace independent logging, threat hunting, credential response and incident investigation.
Quick Recap
What is known—and what is not
- Established: Unit 42 traced CL-STA-1087 activity to at least 2020 and observed targeted searches for military information.
- Established: Sophos reported a nearly two-year Crimson Palace campaign, three clusters and continued activity by at least one cluster through April 2024.
- Established: Microsoft and CSA documented additional China-based or regional espionage activity involving ASEAN military, maritime, government, telecommunications and media targets.
- Not established publicly: a complete list of affected Southeast Asian militaries, a reliable dollar-loss estimate, one continuous campaign linking every report, or a definitive Chinese ministry responsible for all activity.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

