Desk live·
ForensicPost
Nation-state/Espionage/File 24-0911

Sophos Found Three Chinese State-Linked Clusters Inside One Southeast Asian Government

Sophos described an espionage campaign against a Southeast Asian government in which three distinct Chinese state-sponsored clusters operated in the same organisation — building redundant command channels rather than competing for the ground.

Constructed geometry · not a chart of case data
JurisdictionNot establishedthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetUnnamed Southeast Asian government body
ActorClusters Alpha, Bravo, Charlie
D. Kennedy11 min readConfidence: medium2 sources reviewed

In September 2024 Sophos X-Ops published further findings on Operation Crimson Palace, a campaign it describes as running for nearly two years against a high-profile government organisation in Southeast Asia. It identifies three separate clusters of Chinese state-sponsored activity inside that organisation, designated Alpha, Bravo and Charlie.

After a reported hiatus around August 2023, Bravo and Charlie activity resumed. Bravo is described as reappearing in January 2024 and targeting at least eleven further organisations and agencies in the region. The assessed objective is long-term espionage, with the clusters maintaining redundant command-and-control channels. A keylogger described as novel, named Tattletale, is reported as capable of impersonating signed-in users and gathering password policy information.

Three Operators, One Victim, No Collision

We filed one actor per intrusion almost without exception. Where it has recorded more than one, at 23-0715, two ransomware operations arrived at the same company by unrelated routes and neither knew about the other.

This is a different arrangement. Three clusters attributed to one state’s apparatus, in one organisation, building parallel access rather than contesting it. That is not a coincidence of targeting; it reads as separate teams tasked against the same objective, and it implies a coordinating layer this desk cannot see and does not claim to.

Redundancy Is The Tell

Criminal intrusion optimises for speed to payment. Redundant command channels across a network cost effort and add exposure, and buy only one thing: surviving eviction.

We have argued at 23-0724 and 26-0703 that long-dwell state activity is distinguishable from criminal activity by what it invests in rather than by what it takes. Three clusters maintaining independent channels is the clearest expression of that in this database — an operation planning to be there after being found.

The Victim Has No Name In This File

The affected organisation is described only as a high-profile government body in Southeast Asia. The eleven further organisations are not identified either.

That is normal for espionage reporting and it is a real limit. We have recorded at 23-0919 that espionage succeeds by producing no artefact, and this file is the adjacent problem: an artefact exists, and it has been anonymised to the point where no affected population can be identified, no regulator is engaged, and nobody can be told. The desk carries the research and states plainly that it cannot verify who this happened to.

How we reported this

Compiled from Sophos X-Ops’ published Crimson Palace research and contemporaneous reporting of it, listed below. The victim organisation is unnamed in the source and is unnamed here; this desk has not independently verified any element of the account, which with the single-source basis is why the file is graded medium. The characterisation of the activity as Chinese state-sponsored is the vendor’s assessment and is carried as such; this desk attributes nothing to any state. No indicators are reproduced. Corrections: corrections@forensicpost.com.

Sources
  1. Operation Crimson Palace: Sophos threat hunting unveils multiple clusters of Chinese state-sponsored activity targeting Southeast AsiaSophos
  2. Chinese ‘Crimson Palace’ espionage campaign keeps hacking Southeast Asian governmentsThe Record
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary