State-Sponsored Cyber Operations Intensify in Southeast Asia Amid Geopolitical Tensions
Recent state-sponsored cyberattacks in Southeast Asia, attributed to groups like China's Silver Dragon and Earth Kurma, have targeted government and telecommunications sectors, employing sophisticated malware and evasion techniques.
Encrygma is selling the entire Full Cyber Weapon Research of State-Sponsored Cyber Operations Intensify in Southeast Asia Amid Geopolitical Tensions for ₿ 0.10 BTC. Contact us.
Executive Takeaway — TL;DR
- Category:
- State Cyber Warfare
- Severity:
- High
- Actor Type:
- APT
- Geography:
- Southeast Asia
- Confidence:
- Confirmed
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
Executive Summary
In early 2026, Southeast Asia has witnessed a significant escalation in state-sponsored cyber operations, primarily attributed to Chinese threat actors. These campaigns have predominantly targeted government agencies and telecommunications infrastructure, utilizing advanced malware and sophisticated evasion strategies.
Silver Dragon's Cyber-Espionage Campaigns
A Chinese state-sponsored group, identified as Silver Dragon, has been actively conducting cyber-espionage operations since mid-2024. This group, likely affiliated with APT41, has targeted government entities across Southeast Asia, including Myanmar and Malaysia, as well as European nations such as Russia, Poland, Hungary, and Italy. Silver Dragon employs advanced techniques to evade detection, embedding malware within legitimate services like Google Drive and core Windows components, including Windows Update and .NET utilities. Their custom backdoor, GearDoor, utilizes Google Drive for command-and-control operations, disguising communication as regular file uploads and downloads. Infection vectors often involve phishing emails or exploiting internet-facing systems. Post-exploitation tools such as SSHcmd and Cobalt Strike are also employed to maintain access. (techradar.com)
Earth Kurma's Targeted Attacks on Southeast Asian Governments and Telecoms
Another Chinese APT group, Earth Kurma, has been actively targeting government agencies and telecommunications organizations in the Philippines, Vietnam, Thailand, and Malaysia since at least 2020. This group employs custom malware, rootkits, and cloud storage services like Dropbox and OneDrive for data exfiltration and maintaining persistent access. Their tactics include the use of tools such as NBTSCAN, Ladon, FRPC, WMIHACKER, and ICMPinger for lateral movement and network reconnaissance. They deploy a custom keylogger, KMLOG, and use in-memory loaders like DUNLOADER, TESDAT, and DMLOADER to execute payloads without leaving traces on disk. To ensure long-term access and stealthy data exfiltration, Earth Kurma installs rootkits like KRNRAT and MORIYA, using obfuscated communication that mimics legitimate files. In some attacks, the group leveraged the syssetup.dll library to facilitate rootkit installation. (thaicert.or.th)
Implications and Recommendations
The increasing sophistication and frequency of state-sponsored cyberattacks in Southeast Asia underscore the need for enhanced cybersecurity measures. Organizations should implement comprehensive monitoring systems to detect anomalous activities, conduct regular security audits, and ensure timely patching of vulnerabilities. Additionally, fostering international collaboration and information sharing is crucial to effectively counter these evolving cyber threats.
Highlights:
- Chinese hackers hide malware within Windows and Google Drive to hit government targets, Published on Thursday, March 05
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

GopherWhisper APT Escalates Global Espionage Campaign Targeting Government Infrastructure

Jewelbug APT Expands Espionage and Crypto Fraud Operations Across Middle East and Asia

