ThreatCluster

China-linked Hackers Target Southeast Asia's Edge Routers with Custom Malware

First seen 26 May 2026, 16:41 UTC GbhackersCybersecuritynews 83% similarity 75

Article Content

Browse articles
ThreatCluster

A China-linked hacking group is executing an espionage campaign targeting Linux-based edge routers across Southeast Asia. The attackers deploy a custom ELF implant, named router.elf, to gain deep control over network traffic. This operation utilizes a cracked Cobalt Strike Beacon on Windows systems for command-and-control, allowing extensive visibility and manipulation of downstream traffic. The campaign is rated critical in severity due to its potential to affect numerous organizations beyond the initial targets. The full scope of the impact remains unclear, but the operation is ongoing. Security experts are urging immediate attention to this threat as it poses significant risks to critical infrastructure.

Key Points: • China-linked hackers are targeting Linux-based edge routers in Southeast Asia. • The attack employs a custom ELF implant and a cracked Cobalt Strike Beacon. • The campaign has been rated critical due to its extensive impact and ongoing nature.

ThreatCluster AI

Timeline

2026-05-26
China-linked hacking campaign discovered
A sophisticated hacking group was found targeting edge routers in Southeast Asia, compromising network traffic.
Gbhackers
2026-05-26
Custom ELF implant identified
The attackers use a malicious file named router.elf to gain control over compromised devices.
Cybersecuritynews
2026-05-26
Cobalt Strike Beacon utilized
The operation pairs the ELF implant with a cracked Cobalt Strike Beacon for unified command-and-control.
Gbhackers

Community

Browse all →

Tracked Entities in This Story