China-Linked Group CL-STA-1062 Targets Southeast Asian Critical Infrastructure with TinyRCT Backdoor (infosecurity-magazine.com)
- Unit 42 tracked the group as CL-STA-1062, active since March 2022.
- The campaign targeted at least ten organizations between October and December 2025, including two state-owned energy companies.
- TinyRCT allows arbitrary command execution, file exfiltration, screenshots, and self-destruct on C2 command.
- The group also uses SoftEther VPN, Mimikatz, and VNT.
- Researchers link the group to Cisco Talos's UAT-7237, which targeted web hosting in Taiwan.
"Palo Alto Networks Unit 42 reports a China-linked threat actor CL-STA-1062 has been targeting state-owned energy and government entities in Southeast Asia since at least March 2022. In a campaign observed throughout 2025, the group deployed a new backdoor called TinyRCT with command execution, file exfiltration, screenshot capture, and self-destruct capabilities. The group uses open-source tools like SoftEther VPN, Mimikatz, and VNT. Researchers assess with high confidence that this cluster is the same as Cisco Talos's UAT-7237, which targeted web hosting in Taiwan."
no comments yet.