Skip to content
ThreatCluster

China-linked Hackers Target Southeast Asia's Edge Routers with Custom Malware

First seen 26 May 2026, 16:41 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster May 27, 2026 at 16:37 UTC
  • China-linked hackers are targeting Linux-based edge routers in Southeast Asia.
  • The attack employs a custom ELF implant and a cracked Cobalt Strike Beacon.
  • The campaign has been rated critical due to its extensive impact and ongoing nature.

A China-linked hacking group is executing an espionage campaign targeting Linux-based edge routers across Southeast Asia. The attackers deploy a custom ELF implant, named router.elf, to gain deep control over network traffic. This operation utilizes a cracked Cobalt Strike Beacon on Windows systems for command-and-control, allowing extensive visibility and manipulation of downstream traffic. The campaign is rated critical in severity due to its potential to affect numerous organizations beyond the initial targets. The full scope of the impact remains unclear, but the operation is ongoing. Security experts are urging immediate attention to this threat as it poses significant risks to critical infrastructure.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 106d ago How this analysis works

Timeline

2026-05-26
China-linked hacking campaign discovered
A sophisticated hacking group was found targeting edge routers in Southeast Asia, compromising network traffic.
Gbhackers
2026-05-26
Custom ELF implant identified
The attackers use a malicious file named router.elf to gain control over compromised devices.
Cybersecuritynews
2026-05-26
Cobalt Strike Beacon utilized
The operation pairs the ELF implant with a cracked Cobalt Strike Beacon for unified command-and-control.
Gbhackers

More articles in this cluster (2)

Following this threat?

Track Cobalt Strike in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed