China-Linked groups target Southeast Asian government with advanced malware in 2025
2026-03-30T20:51:47Z•5da812264a3ae5abaa715532b06de1a2f9769e90c25e67d3a6fc5c30a10c8e2b
active-exploitationaptchina-linkedcitrixclickfixdarksworddata-leakfortinetinfinity-stealerinfostealeriosmacosmalwarenuitkaphishingrceshinyhuntersta446telegramzero-day
What happened
Multiple high-impact incidents and active exploitation observed: China-linked clusters targeted a Southeast Asian government in 2025 using numerous malware families (HIUPAN, PUBLOAD, EggStremeFuel/Loader, MASOL RAT, PoshRAT, TrackBak Stealer, Hypnosis Loader, FluffyGh0st). Critical vulnerabilities are being actively exploited or probed — Fortinet FortiClient EMS (CVE-2026-21643) is under active exploitation for RCE via SQL injection, and Citrix NetScaler ADC/Gateway (CVE-2026-3055) is being probed for a memory overread that may leak sensitive data. An alleged Telegram zero-click RCE (ZDI-CAN-3
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 5da812264a3ae5abaa715532b06de1a2f9769e90c25e67d3a6fc5c30a10c8e2b
- Enrichment time
- 2026-03-30T20:51:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.