News Room
16
Share
highState Cyber Warfare

State-Sponsored Cyber Operations Intensify in Southeast Asia Amid Geopolitical Tensions

Recent state-sponsored cyberattacks in Southeast Asia, attributed to groups like China's Silver Dragon and Earth Kurma, have targeted government and telecommunications sectors, employing sophisticated malware and evasion techniques.

₿

Encrygma is selling the entire Full Cyber Weapon Research of State-Sponsored Cyber Operations Intensify in Southeast Asia Amid Geopolitical Tensions for ₿ 0.10 BTC. Contact us.

31 March 2026Last updated 31 March 20265 min readRaptor Cyber Intelligence
E
Encrygma AI Cyber Weapons Advisory Services : ₿ 0.10 BTCWe sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
State Cyber Warfare
Severity:
High
Actor Type:
APT
Geography:
Southeast Asia
Confidence:
Confirmed
Source:
Raptor Cyber Intelligence
Read Time:
5 min

Executive Summary

In early 2026, Southeast Asia has witnessed a significant escalation in state-sponsored cyber operations, primarily attributed to Chinese threat actors. These campaigns have predominantly targeted government agencies and telecommunications infrastructure, utilizing advanced malware and sophisticated evasion strategies.

Silver Dragon's Cyber-Espionage Campaigns

A Chinese state-sponsored group, identified as Silver Dragon, has been actively conducting cyber-espionage operations since mid-2024. This group, likely affiliated with APT41, has targeted government entities across Southeast Asia, including Myanmar and Malaysia, as well as European nations such as Russia, Poland, Hungary, and Italy. Silver Dragon employs advanced techniques to evade detection, embedding malware within legitimate services like Google Drive and core Windows components, including Windows Update and .NET utilities. Their custom backdoor, GearDoor, utilizes Google Drive for command-and-control operations, disguising communication as regular file uploads and downloads. Infection vectors often involve phishing emails or exploiting internet-facing systems. Post-exploitation tools such as SSHcmd and Cobalt Strike are also employed to maintain access. (techradar.com)

Earth Kurma's Targeted Attacks on Southeast Asian Governments and Telecoms

Another Chinese APT group, Earth Kurma, has been actively targeting government agencies and telecommunications organizations in the Philippines, Vietnam, Thailand, and Malaysia since at least 2020. This group employs custom malware, rootkits, and cloud storage services like Dropbox and OneDrive for data exfiltration and maintaining persistent access. Their tactics include the use of tools such as NBTSCAN, Ladon, FRPC, WMIHACKER, and ICMPinger for lateral movement and network reconnaissance. They deploy a custom keylogger, KMLOG, and use in-memory loaders like DUNLOADER, TESDAT, and DMLOADER to execute payloads without leaving traces on disk. To ensure long-term access and stealthy data exfiltration, Earth Kurma installs rootkits like KRNRAT and MORIYA, using obfuscated communication that mimics legitimate files. In some attacks, the group leveraged the syssetup.dll library to facilitate rootkit installation. (thaicert.or.th)

Implications and Recommendations

The increasing sophistication and frequency of state-sponsored cyberattacks in Southeast Asia underscore the need for enhanced cybersecurity measures. Organizations should implement comprehensive monitoring systems to detect anomalous activities, conduct regular security audits, and ensure timely patching of vulnerabilities. Additionally, fostering international collaboration and information sharing is crucial to effectively counter these evolving cyber threats.

Highlights:

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo