Chinese Hackers Target Southeast Asian Militaries with AppleChris and MemFun Malware

2026-03-14T01:24:12Zbfb22d2b6d8842189a6e13a528378cff03d227945bb5ec3cbcbac6e0b7bebe96
AppleChrisChina-APTChrome-zero-dayCrackArmorMemFunSEO-poisoningSocksEscortSoutheast-AsiaVeeamcredential-theftespionagemalwaren8nstate-sponsoredsupply-chain

What happened

A broad set of security incidents and disclosures: a suspected China-backed espionage cluster (CL-STA-1087) targeting Southeast Asian militaries with AppleChris and MemFun malware; multiple high-severity product vulnerabilities fixed (Chrome zero-day CVE-2026-3909, Veeam Backup & Replication RCEs including CVE-2026-21666/21667, critical n8n RCEs CVE-2026-27577 and CVE-2026-27493, and others); large-scale law‑enforcement disruptions (45,000 malicious IPs takedown; SocksEscort proxy botnet dismantled); active credential‑theft campaigns (SEO-poisoned Trojan VPN installers, new Rust VENON banking‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
bfb22d2b6d8842189a6e13a528378cff03d227945bb5ec3cbcbac6e0b7bebe96
Enrichment time
2026-03-14T01:24:12Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.