[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"detail-sidebar-cat-0-en-105":3,"doc-seo-137813-105":59,"doc-detail-137813-en":131},{"code":4,"msg":5,"data":6},0,"success",[7,13,18,23,28,33,38,43,48,51,55],{"id":8,"doc_module":4,"doc_module_name":9,"category_name":10,"show_sort_weight":11,"slug":12},1,"Document","Story & Novel",90,"story-novel",{"id":14,"doc_module":4,"doc_module_name":9,"category_name":15,"show_sort_weight":16,"slug":17},2,"Literature",80,"literature",{"id":19,"doc_module":4,"doc_module_name":9,"category_name":20,"show_sort_weight":21,"slug":22},4,"Exam",70,"exam",{"id":24,"doc_module":4,"doc_module_name":9,"category_name":25,"show_sort_weight":26,"slug":27},5,"Comic",60,"comic",{"id":29,"doc_module":4,"doc_module_name":9,"category_name":30,"show_sort_weight":31,"slug":32},6,"Technology",50,"technology",{"id":34,"doc_module":4,"doc_module_name":9,"category_name":35,"show_sort_weight":36,"slug":37},7,"Healthcare",40,"healthcare",{"id":39,"doc_module":4,"doc_module_name":9,"category_name":40,"show_sort_weight":41,"slug":42},8,"Research & Report",30,"research-report",{"id":44,"doc_module":4,"doc_module_name":9,"category_name":45,"show_sort_weight":46,"slug":47},9,"Religion & Spirituality",20,"religion-spirituality",{"id":46,"doc_module":4,"doc_module_name":9,"category_name":49,"show_sort_weight":46,"slug":50},"World Cup","world-cup",{"id":52,"doc_module":4,"doc_module_name":9,"category_name":53,"show_sort_weight":52,"slug":54},10,"Lifestyle","lifestyle",{"id":56,"doc_module":4,"doc_module_name":9,"category_name":57,"show_sort_weight":24,"slug":58},19,"General","general",{"code":4,"msg":60,"data":61},"ok",{"site_id":62,"language":63,"slug":64,"title":65,"keywords":66,"description":67,"schema_data":68,"social_meta":124,"head_meta":126,"extra_data":128,"updated_unix":130},105,"en","cyber-threat-analysis-china-chinese-state-sponsored-cyber-espionage-activity-supports-expansion-of-regional-power-and-influence-in-southeast-asia","CYBER THREAT ANALYSIS - CHINA - Chinese State-Sponsored Cyber Espionage Activity Supports Expansion of Regional Power and Influence in Southeast Asia","","Profiles trends in Chinese state-sponsored cyber espionage targeting Southeast Asian countries, identified through large-scale automated network traffic analytics and expert analysis. Draws on multiple threat-intelligence data sources including Recorded Future Platform and security-focused services. Highlights 2021 intrusions by the tracked TAG-161 (TAG-16) using custom malware families such as FunnyDream and Chinoxy, and also two suspected campaigns targeting Laos and Cambodia to support Belt and Road Initiative objectives. Includes key judgments and contextual background on regional targeting and estimated victims.",{"@graph":69,"@context":123},[70,84,106],{"@type":71,"itemListElement":72},"BreadcrumbList",[73,77,79,82],{"item":74,"name":75,"@type":76,"position":8},"https://docshare.wps.com","Home","ListItem",{"item":78,"name":9,"@type":76,"position":14},"https://docshare.wps.com/document/",{"item":80,"name":40,"@type":76,"position":81},"https://docshare.wps.com/document/research-report/",3,{"item":83,"name":65,"@type":76,"position":19},"https://docshare.wps.com/document/cyber-threat-analysis-china-chinese-state-sponsored-cyber-espionage-activity-supports-expansion-of-regional-power-and-influence-in-southeast-asia/137813/",{"url":83,"name":65,"@type":85,"image":86,"author":91,"headline":65,"publisher":94,"fileFormat":97,"inLanguage":63,"description":67,"dateModified":98,"datePublished":99,"encodingFormat":97,"isAccessibleForFree":100,"interactionStatistic":101},"DigitalDocument",{"url":87,"@type":88,"width":89,"height":90},"https://docshare.wps.com/thumbnails/cyber-threat-analysis-china-chinese-state-sponsored-cyber-espionage-activity-supports-expansion-of-regional-power-and-influence-in-southeast-asia/137813.png","ImageObject",300,407,{"name":92,"@type":93},"Oliver","Person",{"url":74,"name":95,"@type":96},"DocShare","Organization","application/pdf","2026-09-20","2026-08-23",true,{"@type":102,"interactionType":103,"userInteractionCount":105},"InteractionCounter",{"@type":104},"ViewAction",11,{"@type":107,"mainEntity":108},"FAQPage",[109,115,119],{"name":110,"@type":111,"acceptedAnswer":112},"Which actors and organizations are targeted in the report?","Question",{"text":113,"@type":114},"The report highlights Chinese state-sponsored cyber espionage targeting government and private sector organizations across Southeast Asia, including military and foreign affairs-related entities.","Answer",{"name":116,"@type":111,"acceptedAnswer":117},"What is TAG-161 (TAG-16) and what did it compromise?",{"text":118,"@type":114},"TAG-161 (TAG-16) is a tracked activity group reported as compromising multiple high-profile military and government organizations across Southeast Asia during 2021 using custom malware families such as FunnyDream and Chinoxy.",{"name":120,"@type":111,"acceptedAnswer":121},"How are the Laos and Cambodia campaigns linked to broader Chinese objectives?",{"text":122,"@type":114},"The report describes two suspected intrusion campaigns targeting entities in Laos and Cambodia, likely intended to support Belt and Road Initiative objectives, with victims including SEZ-related organizations in Laos and Sihanoukville Autonomous Port in Cambodia.","https://schema.org",{"og:url":83,"og:type":125,"og:title":65,"og:site_name":95,"og:description":67},"article",{"robots":127,"canonical":83},"index,follow",{"doc_id":129,"site_id":62},137813,1787447969,{"code":4,"msg":5,"data":132},{"doc_id":129,"user_id":133,"nickname":92,"user_avatar":134,"doc_module":4,"category_id":39,"category_name":40,"doc_title":65,"doc_description":67,"doc_content":135,"file_id":136,"file_url":137,"file_type":138,"file_size":139,"view_count":105,"is_deleted":4,"is_public":8,"is_downloadable":8,"audit_status":8,"page_count":140,"language":141,"language_code":63,"site_id":62,"html_lang":63,"table_of_contents":142,"faqs":143,"seo_title":144,"seo_description":67,"update_tm":130,"read_time":145},8796095461610,"https://ap-avatar.wpscdn.com/davatar_276721f389ce27ea32af1340a28f341c","CYBER THREAT ANALYSIS  \nCHINA  \nChinese State-Sponsored Cyber Espionage Activity Supports Expansion of Regional Power and Influence in Southeast Asia  \nCYBER THREAT ANALYSIS | CHINA  \nThis report profiles trends in Chinese state-sponsored cyber espionage activity targeting Southeast Asian countries. The activity was identified through large-scale automated network traffic analytics and expert analysis. Data sources include the Recorded Future Platform, SecurityTrails, DomainTools, PolySwarm, Farsight, Team Cymru, and common open-source tools and techniques. The research will be of most interest to individuals engaged in strategic and operational intelligence relating to the activities of Chinese military and foreign intelligence agencies in cyberspace and network defenders with a presence in Southeast Asia.  \nExecutive Summary  \nRecorded Future’s Insikt Group tracks Chinese state-sponsored cyber espionage operations targeting government and private sector organizations across Southeast Asia. In this report, we highlight multiple examples of activity reported to Recorded Future clients throughout 2021. The identified intrusion campaigns almost certainly support key strategic aims of the Chinese government, such as gathering intelligence on countries engaged in South China Sea territorial disputes or related to projects and countries strategically important to the Belt and Road Initiative (BRI) .  \nThe activity highlighted includes a group we track as Threat Activity Group 16 (TAG-161), which has compromised several high-profile military and government organizations across Southeast Asia throughout 2021 using custom malware families such as FunnyDream and Chinoxy. Many of the governments targeted by TAG-16 are engaged in ongoing disputes with China over territorial claims in the South China Sea.  \nAdditionally, we highlight 2 separate suspected Chinese state-sponsored intrusion campaigns targeting entities in Laos and Cambodia. Both are likely intended to support BRI objectives. Victims in these 2 respective campaigns include the National Committee for Special Economic Zones (SEZs) and National Enterprise Database (NED) in Laos and Cambodia’s Sihanoukville Autonomous Port (PAS) .  \n1 Insikt Group publicly names a new threat activity group or campaign, such as RedFoxtrot, typically when analysts have data corresponding to at least 3 points on the Diamond Model of Intrusion Analysis with at least medium confidence. We will occasionally report on significant activity using a temporary activity clustering name such as TAG-16, where the activity is new and significant but doesn’t map to existing groupings and hasn’t yet graduated or merged into an established activity group.  \nKey Judgments  \n• Our research highlights China’s continued strategic and tactical interest in government and private sector organizations in Southeast Asia. This targeting is almost certainly linked to a range of objectives intended to support a deepening of regional influence, including traditional intelligence gathering against regional rivals and allies, economic intelligence gathering against BRI-linked targets, and the South China Sea disputes.  \n• The operational tasking of TAG-16 is likely linked, in part, to gathering intelligence on South China Sea-related issues. Notably, Insikt Group identified the compromise of navies, prime minister’s offices, ministries of defense, and ministries of foreign affairs across several countries with a presence in the South China Sea.  \n• The targeting of Cambodia’s Sihanoukville Autonomous Port and Laos’s National Committee for SEZs is likely linked to China’s wider strategic objectives under the BRI. PAS has high strategic significance given its location along the Maritime Silk Road route, while the Lao government has promoted the development of SEZs as an entry point for private sector development, including domestic and foreign direct investment (FDI) .  \n1 CTA-CN-2021-1208 Recorded Future® | [www. recordedfuture.c","cbCaiqJg4eoefoUm","https://ap.wps.com/l/cbCaiqJg4eoefoUm","pdf",1746201,13,"English","# Executive Summary\n# Key Judgments\n# Background","[{\"question\":\"Which actors and organizations are targeted in the report?\",\"answer\":\"The report highlights Chinese state-sponsored cyber espionage targeting government and private sector organizations across Southeast Asia, including military and foreign affairs-related entities.\"},{\"question\":\"What is TAG-161 (TAG-16) and what did it compromise?\",\"answer\":\"TAG-161 (TAG-16) is a tracked activity group reported as compromising multiple high-profile military and government organizations across Southeast Asia during 2021 using custom malware families such as FunnyDream and Chinoxy.\"},{\"question\":\"How are the Laos and Cambodia campaigns linked to broader Chinese objectives?\",\"answer\":\"The report describes two suspected intrusion campaigns targeting entities in Laos and Cambodia, likely intended to support Belt and Road Initiative objectives, with victims including SEZ-related organizations in Laos and Sihanoukville Autonomous Port in Cambodia.\"}]","CYBER THREAT ANALYSIS - CHINA - Chinese State-Sponsored Cyber Espionage Activity Supports Expansion of Regional Power and Influence in Southeast Asia | PDF",33]