China-Linked groups target Southeast Asian government with advanced malware in 2025

2026-03-30T20:51:47Z5da812264a3ae5abaa715532b06de1a2f9769e90c25e67d3a6fc5c30a10c8e2b
active-exploitationaptchina-linkedcitrixclickfixdarksworddata-leakfortinetinfinity-stealerinfostealeriosmacosmalwarenuitkaphishingrceshinyhuntersta446telegramzero-day

What happened

Multiple high-impact incidents and active exploitation observed: China-linked clusters targeted a Southeast Asian government in 2025 using numerous malware families (HIUPAN, PUBLOAD, EggStremeFuel/Loader, MASOL RAT, PoshRAT, TrackBak Stealer, Hypnosis Loader, FluffyGh0st). Critical vulnerabilities are being actively exploited or probed — Fortinet FortiClient EMS (CVE-2026-21643) is under active exploitation for RCE via SQL injection, and Citrix NetScaler ADC/Gateway (CVE-2026-3055) is being probed for a memory overread that may leak sensitive data. An alleged Telegram zero-click RCE (ZDI-CAN-3

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
5da812264a3ae5abaa715532b06de1a2f9769e90c25e67d3a6fc5c30a10c8e2b
Enrichment time
2026-03-30T20:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.