CL-STA-1087 targets military capabilities since 2020
2026-03-17T14:51:47Z•abbbea347db4cb5eb54d02c0a4f15d219de9829c25fab709af3b5910cc64fbac
AMOSAPTAppArmorAppleChrisCISACL-STA-1087CVE-2025-47813ClickFixCrackArmorDRILLAPPKEVLaundry_BearLinux_kernelMemFunMicrosoft_environmentPayload_RansomwareRoyal_Bahrain_HospitalSteam_malware_investigation,FBI,Signal_account_takeover,Android_StrykerWing_FTPdevice_wipeinfostealermacOSprivilege_escalationransomware
What happened
A recent SecurityAffairs feed highlights multiple high-impact cyber incidents and vulnerability disclosures: China-linked APT CL-STA-1087 has targeted Southeast Asian military organizations since 2020 using AppleChris and MemFun malware; a Russia-linked campaign deployed the DRILLAPP backdoor against Ukrainian targets while abusing Edge debugging for stealth; and ClickFix social-engineering attacks are shifting toward macOS with ChatGPT-based lures and new infostealers (e.g., AMOS). Major operational incidents include a malware-free remote wipe of tens of thousands of employee devices in Stry
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- abbbea347db4cb5eb54d02c0a4f15d219de9829c25fab709af3b5910cc64fbac
- Enrichment time
- 2026-03-17T14:51:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.