Skip to main content

Threats Tagged 'southeast asia'

View all threats tagged with 'southeast asia'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: southeast asia

Threats Tagged 'southeast asia'

Click on any threat for detailed analysis and mitigation recommendations

Since late 2025, government and diplomatic entities in Southeast Asia have been targeted by sophisticated attacks involving GoSerpent, a Go-based RAT with proxy capabilities. The malware receives encrypted arguments and deploys additional tools for data collection and credential dumping. GoSerpent has been active since 2021, with newer variants using AES-CBC encryption and ChaCha20 for communications. The campaign involves multiple stages: initial deployment of GoSerpent and ThumbcacheService to collect sensitive files, credential dumping via Mimikatz and QuarksDumpLocalHash, followed by deployment of Stowaway RAT in May 2026 and TmcLoader/TmcPayload for stealthy data exfiltration through network shares. The integrated toolset demonstrates sophisticated operational planning, with attackers leveraging Alibaba Cloud and UCLOUD HK infrastructure while exhibiting possible connections to the TetrisPhantom threat actor.

Join the discussion

RedHook is an Android Remote Access Trojan that has re-emerged with significant enhancements, particularly in privilege abuse capabilities. The malware autonomously exploits Android's ADB Wireless Debugging features to obtain shell-level access, integrating the Shizuku framework to execute protected system APIs. Recent activity shows expansion beyond Vietnam to Indonesia, targeting Southeast Asian users through spoofed government and financial websites. Malicious APKs are hosted on trusted platforms like AWS S3 and GitHub repositories. The current version supports 53 distinct server-issued commands and employs sophisticated persistence mechanisms including foreground activity spoofing, silent media playback, and cross-process monitoring. Distribution relies on social engineering via phone calls and messaging applications, tricking victims into downloading malicious APKs and enabling Accessibility services under false pretenses.

Join the discussion

A sophisticated Android malware campaign has been identified conducting carrier billing fraud through premium SMS abuse across Malaysia, Thailand, Romania, and Croatia. The operation comprises nearly 250 malicious applications that selectively target users based on their mobile operators, silently subscribing victims to premium services without consent. The malware demonstrates advanced capabilities including precise regional targeting with hardcoded SIM operator validation, automated subscription workflows using WebView manipulation and JavaScript injection, OTP interception via abuse of Google's SMS Retriever API, and Telegram-based exfiltration of device metadata. The campaign impersonates popular applications including Facebook, Instagram, TikTok, Minecraft, and Grand Theft Auto to lure victims. Active from March 2025 through January 2026, the operation employs three distinct variants with increasing levels of sophistication, utilizing distributed command and control infrastructure and systematic refer...

Join the discussion

Check Point Research has identified a Chinese-nexus advanced persistent threat group named Silver Dragon, targeting organizations in Southeast Asia and Europe since mid-2024. The group, likely operating under APT41, exploits public-facing servers and uses phishing emails for initial access. They deploy custom tools including GearDoor, a backdoor using Google Drive for command and control, SSHcmd for remote access, and SilverScreen for covert screen monitoring. Silver Dragon primarily focuses on government entities, utilizing Cobalt Strike beacons and DNS tunneling for communication. The group's sophisticated tactics and evolving toolkit demonstrate a well-resourced and adaptable threat actor.

Join the discussion

The HoneyMyte APT group has enhanced its toolset with an updated CoolClient backdoor and new data stealing capabilities. The group targeted government entities in Asia and Europe, particularly Southeast Asia. CoolClient now features clipboard monitoring, HTTP proxy credential sniffing, and plugin support for extended functionality. HoneyMyte also deployed browser login data stealers and document theft scripts. The campaign's focus has shifted towards active surveillance, including keylogging, clipboard data collection, and proxy credential harvesting. Organizations are advised to remain vigilant against HoneyMyte's evolving toolkit, which includes CoolClient, PlugX, ToneShell, Qreverse, and LuminousMoth malware families.

Join the discussion

A new ransomware called Osiris was used in an attack on a major food service franchisee operator in Southeast Asia in November 2025. The ransomware shares similarities with previous Inc ransomware attacks, including the use of Wasabi buckets for data exfiltration and a specific version of Mimikatz. Osiris has typical ransomware functions, uses a hybrid encryption scheme, and drops a ransom note. The attack chain involved data exfiltration using Rclone, deployment of dual-use tools, and the use of a malicious driver called Abyssworker or Poortry. The attackers employed bring-your-own-vulnerable-driver (BYOVD) techniques to disable security software. While the impact of Osiris on the ransomware landscape remains uncertain, it appears to be wielded by experienced attackers with potential links to Inc ransomware or its affiliates.

Join the discussion

ESET researchers have uncovered a new China-aligned APT group named LongNosedGoblin targeting governmental entities in Southeast Asia and Japan for cyberespionage. The group employs a varied custom toolset of C#/.NET applications and abuses Group Policy for lateral movement. Key tools include NosyHistorian for collecting browser history, NosyDoor backdoor using cloud services as C&C, and NosyStealer for exfiltrating browser data. The attackers also utilize techniques like AppDomainManager injection and AMSI bypassing. LongNosedGoblin has been active since at least September 2023, showing ongoing campaigns throughout 2024 and 2025. The research provides detailed analysis of the group's malware and tactics, including potential sharing of the NosyDoor backdoor among multiple China-aligned actors.

Join the discussion

A newly discovered China-aligned APT group named LongNosedGoblin has been targeting governmental entities in Southeast Asia and Japan for cyberespionage purposes. The group employs a varied custom toolset consisting mainly of C#/.NET applications and notably uses Group Policy to deploy malware and move laterally across compromised networks. Their main tools include NosyHistorian for collecting browser history, NosyDoor backdoor using cloud services as C&C, and NosyStealer for exfiltrating browser data. The group has been active since at least September 2023 and uses techniques like AMSI bypassing and living-off-the-land tactics. LongNosedGoblin's campaigns involve multiple stages of execution and various malware components, showcasing a sophisticated approach to cyber espionage operations.

Join the discussion

The 'GhostAd' campaign is a large-scale Android adware threat that infiltrated Google Play with seemingly benign apps embedding persistent background advertising engines. These apps exploited Android foreground services, job schedulers, and continuous ad refreshing to maintain presence and aggressively display ads without user interaction, causing significant battery drain, degraded device performance, and difficulty in removal. Although primarily impacting users in East and Southeast Asia, the adware's use of legitimate advertising SDKs complicates detection and removal. Google has removed the malicious apps and disabled them via Google Play Protect. European organizations with Android device fleets could face indirect impacts such as reduced device availability and user productivity if similar apps spread. Mitigation requires proactive app vetting, enhanced endpoint monitoring for abnormal resource usage, and user education on app permissions and removal techniques. Countries with high Android adoption and significant Google Play usage, such as Germany, France, and the UK, are more likely to be affected if the campaign expands. Given the medium severity rating, the threat poses a moderate risk primarily through resource exhaustion and user disruption without direct data compromise or remote exploitation.

Join the discussion

WEBJACK is a malware campaign targeting Microsoft IIS servers by deploying BadIIS malware modules to conduct SEO poisoning and fraud. The attackers hijack high-profile websites, including government and educational institutions, redirecting users to gambling sites. The campaign selectively serves malicious content to search engine crawlers while redirecting or blocking normal visitors, leveraging legitimate IIS modules for stealth. Originating from a Chinese-speaking threat actor, it primarily affects Southeast Asia and Latin America, with a focus on Vietnamese-language targets. Although no known exploits are publicly reported, the campaign uses advanced tools such as Cobalt Strike and XLANY Loader. The threat demonstrates evolving IIS hijacking techniques and abuse of legitimate security tools for monetization. European organizations could be at risk if targeted due to the use of IIS servers and the potential for reputational damage and fraud. Mitigation requires specific IIS module monitoring, integrity checks, and enhanced web server security. Countries with significant IIS usage and strategic government or educational targets, such as Germany, France, and the UK, are more likely to be affected. The threat severity is assessed as medium given the targeted nature, impact on availability and integrity, and moderate ease of exploitation without user interaction.

Join the discussion

Showing 1 to 10 of 14 results

Filters:Tag: southeast asia
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses