China-Nexus Hackers Skulk in Southeast Asian Military Orgs for Years

2026-03-17T14:51:41Z540e16e4761d9a8e707c950c6528c3ed52bbba5689ab67712b4214b66cd0d6c9
China-linkedCiscoGlassWormINCIran-linkedMicrosoftattack-surfacebanking-trojancloud-securitycyberespionagegithub-actiongoogle-cloudlivechatmalwarenation-statepatch-managementphishingransomwaresupply-chaintag-poisoningvulnerabilities

What happened

DarkReading's mid‑March 2026 roundup highlights an uptick in nation‑state cyberespionage and high‑impact criminal activity across multiple regions and vectors. Key items: China‑nexus actors maintaining long‑term access to Southeast Asian military targets (and pivoting to Qatar), evolving GlassWorm extensions that hide in dependencies, supply‑chain compromise via a GitHub Action (tag poisoning), banking Trojan campaigns targeting Brazil's Pix, LiveChat social‑engineering phishing, and INC ransomware strikes on Oceania healthcare. The briefing also notes widespread vulnerabilities and patching (

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
540e16e4761d9a8e707c950c6528c3ed52bbba5689ab67712b4214b66cd0d6c9
Enrichment time
2026-03-17T14:51:41Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.