Find notable cyber news and cases, enriched with sources, timelines, and signals.

CL-STA-1062 Southeast Asia critical infrastructure campaign using TinyRCT

Campaign
First reported
Last updated
Happening score
H score 18
2 unique sources, 2 articles

Summary

Hide ▲

A China-linked campaign by CL-STA-1062 is targeting government entities and critical infrastructure across Southeast Asia, with activity reaching state-owned enterprises in the energy and government sectors. Palo Alto Networks Unit 42 tied the operation to the previously undocumented TinyRCT backdoor and said the activity has been active since at least March 2022 and remained visible through 2025. The campaign used ASPX web shells, SoftEther VPN, Mimikatz, and VNT to support access, reconnaissance, and exfiltration. Unit 42 said it detected breaches of at least 10 organizations in the region between October and December 2025.

Related Happenings

TinyRCT backdoor used in CL-STA-1062 Southeast Asia intrusions

Malware Activity
H score15 First: 26.06.2026 19:21 Last: 26.06.2026 19:21 Sources 1

How related: While they frequently use common open-source tools such as SoftEther VPN, Mimikatz, and VNT, they have recently introduced TinyRCT, a bespoke, previously undocumented backdoor.

About this happening: The newly documented TinyRCT backdoor gives CL-STA-1062 a custom remote-access payload for government and critical-infrastructure targets in Southeast Asia, expanding...

TinyRCT backdoor with persistence, exfiltration, and self-deletion

Malware Activity
H score22 First: 26.06.2026 13:30 Last: 26.06.2026 13:30 Sources 1

How related: Additionally, the threat group used TinyRCT for the first time, a previously undocumented backdoor designed to provide persistent access and control over compromised systems.

About this happening: The TinyRCT backdoor appeared in a 2025 intrusion operation, adding stealthy persistent access and control to the attackers' toolkit. It also supports command ex...

Webworm multi-country targeting campaign against government and enterprise victims

Campaign
H score38 First: 20.05.2026 15:51 Last: 20.05.2026 15:51 Sources 1

About this happening: Webworm is running a multi-country targeting campaign against government agencies and enterprises, expanding the risk of persistent access across several regions. The...

Red Menshen telecom espionage campaign

Campaign
H score33 First: 26.03.2026 19:40 Last: 26.03.2026 19:40 Sources 1

About this happening: A China-nexus Red Menshen operation has sustained covert access in telecom networks across the Middle East and Asia, increasing the risk of government espion...

UNC2814 multi-country cyber espionage campaign

Campaign
H score25 First: 25.02.2026 19:46 Last: 25.02.2026 19:46 Sources 1

About this happening: The UNC2814 espionage campaign was disrupted after it was tied to breaches at 53 organizations across 42 countries, reducing infrastructure used for long-term access a...

Timeline

  1. 25.06.2026 03:00 3 articles · 21d ago

    Unit 42 uncovers CL-STA-1062 campaign targeting Southeast Asian critical infrastructure

    Initial Disclosure

    Palo Alto Networks Unit 42 identified a China-linked campaign by CL-STA-1062 targeting government entities and critical infrastructure in Southeast Asia, including state-owned enterprises in the energy and government sectors. The researchers said the activity had been active since at least March 2022, was observed throughout 2025, and involved the previously undocumented TinyRCT backdoor alongside SoftEther VPN, Mimikatz, and VNT.

    Show sources