CL-STA-1087 targets military capabilities since 2020

2026-03-17T14:51:47Zabbbea347db4cb5eb54d02c0a4f15d219de9829c25fab709af3b5910cc64fbac
AMOSAPTAppArmorAppleChrisCISACL-STA-1087CVE-2025-47813ClickFixCrackArmorDRILLAPPKEVLaundry_BearLinux_kernelMemFunMicrosoft_environmentPayload_RansomwareRoyal_Bahrain_HospitalSteam_malware_investigation,FBI,Signal_account_takeover,Android_StrykerWing_FTPdevice_wipeinfostealermacOSprivilege_escalationransomware

What happened

A recent SecurityAffairs feed highlights multiple high-impact cyber incidents and vulnerability disclosures: China-linked APT CL-STA-1087 has targeted Southeast Asian military organizations since 2020 using AppleChris and MemFun malware; a Russia-linked campaign deployed the DRILLAPP backdoor against Ukrainian targets while abusing Edge debugging for stealth; and ClickFix social-engineering attacks are shifting toward macOS with ChatGPT-based lures and new infostealers (e.g., AMOS). Major operational incidents include a malware-free remote wipe of tens of thousands of employee devices in Stry­

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
abbbea347db4cb5eb54d02c0a4f15d219de9829c25fab709af3b5910cc64fbac
Enrichment time
2026-03-17T14:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.