Billbug Cyberespionage Campaign Targets Southeast Asia

Red | Attack Report
Download PDF

Billbug, a Chinese cyberespionage group, targeted Southeast Asian government and infrastructure sectors from August 2024 to February 2025. They used spear-phishing, custom malware like Sagerunex, and stealthy techniques such as DLL sideloading. Tools like ChromeKatz and Zrok enabled credential theft and covert remote access. Active since at least 2009, Billbug poses a significant long-term threat to national security through sustained espionage operations.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox