Unit 42 researchers detail a persistent cyberespionage campaign targeting a Southeast Asian government organization between June and August 2025. Three distinct China-aligned threat clusters operated simultaneously against the same target: Stately Taurus used USB-propagated USBFect/HIUPAN malware to deploy the PUBLOAD backdoor

16m read timeFrom unit42.paloaltonetworks.com
Post cover image
Table of contents
Executive SummarySoutheast Asian Government TargetingStately Taurus - PUBLOAD ActivityCL-STA-1048 - Espionage ToolkitCL-STA-1049 - Stealthy Loader and FluffyGh0st RAT DeploymentConclusionIndicators of CompromiseAdditional Resources

Sort: