0x

guest@0xbase ~$ read-only mode. Posting requires EU location.

China-Linked Group CL-STA-1062 Targets Southeast Asian Critical Infrastructure with TinyRCT Backdoor (infosecurity-magazine.com)

· 31d ago · Report · Spotlight this ·
0xBASE INTEL BRIEF
  • Unit 42 tracked the group as CL-STA-1062, active since March 2022.
  • The campaign targeted at least ten organizations between October and December 2025, including two state-owned energy companies.
  • TinyRCT allows arbitrary command execution, file exfiltration, screenshots, and self-destruct on C2 command.
  • The group also uses SoftEther VPN, Mimikatz, and VNT.
  • Researchers link the group to Cisco Talos's UAT-7237, which targeted web hosting in Taiwan.

"Palo Alto Networks Unit 42 reports a China-linked threat actor CL-STA-1062 has been targeting state-owned energy and government entities in Southeast Asia since at least March 2022. In a campaign observed throughout 2025, the group deployed a new backdoor called TinyRCT with command execution, file exfiltration, screenshot capture, and self-destruct capabilities. The group uses open-source tools like SoftEther VPN, Mimikatz, and VNT. Researchers assess with high confidence that this cluster is the same as Cisco Talos's UAT-7237, which targeted web hosting in Taiwan."

Discussion Matrix

0 segments

no comments yet.