CL-STA-1062 Southeast Asia critical infrastructure campaign using TinyRCT
Campaign
Summary
Hide ▲
Show ▼
A China-linked campaign by CL-STA-1062 is targeting government entities and critical infrastructure across Southeast Asia, with activity reaching state-owned enterprises in the energy and government sectors. Palo Alto Networks Unit 42 tied the operation to the previously undocumented TinyRCT backdoor and said the activity has been active since at least March 2022 and remained visible through 2025. The campaign used ASPX web shells, SoftEther VPN, Mimikatz, and VNT to support access, reconnaissance, and exfiltration. Unit 42 said it detected breaches of at least 10 organizations in the region between October and December 2025.
Related Happenings
TinyRCT backdoor used in CL-STA-1062 Southeast Asia intrusions
Malware Activity
H score15
First: 26.06.2026 19:21
Last: 26.06.2026 19:21
Sources 1
How related:
While they frequently use common open-source tools such as SoftEther VPN, Mimikatz, and VNT, they have recently introduced TinyRCT, a bespoke, previously undocumented backdoor.
About this happening:
The newly documented TinyRCT backdoor gives CL-STA-1062 a custom remote-access payload for government and critical-infrastructure targets in Southeast Asia, expanding...
TinyRCT backdoor used in CL-STA-1062 Southeast Asia intrusions
Malware ActivityHow related: While they frequently use common open-source tools such as SoftEther VPN, Mimikatz, and VNT, they have recently introduced TinyRCT, a bespoke, previously undocumented backdoor.
About this happening: The newly documented TinyRCT backdoor gives CL-STA-1062 a custom remote-access payload for government and critical-infrastructure targets in Southeast Asia, expanding...
TinyRCT backdoor with persistence, exfiltration, and self-deletion
Malware Activity
H score22
First: 26.06.2026 13:30
Last: 26.06.2026 13:30
Sources 1
How related:
Additionally, the threat group used TinyRCT for the first time, a previously undocumented backdoor designed to provide persistent access and control over compromised systems.
About this happening:
The TinyRCT backdoor appeared in a 2025 intrusion operation, adding stealthy persistent access and control to the attackers' toolkit. It also supports command ex...
TinyRCT backdoor with persistence, exfiltration, and self-deletion
Malware ActivityHow related: Additionally, the threat group used TinyRCT for the first time, a previously undocumented backdoor designed to provide persistent access and control over compromised systems.
About this happening: The TinyRCT backdoor appeared in a 2025 intrusion operation, adding stealthy persistent access and control to the attackers' toolkit. It also supports command ex...
Webworm multi-country targeting campaign against government and enterprise victims
Campaign
H score38
First: 20.05.2026 15:51
Last: 20.05.2026 15:51
Sources 1
About this happening:
Webworm is running a multi-country targeting campaign against government agencies and enterprises, expanding the risk of persistent access across several regions. The...
Webworm multi-country targeting campaign against government and enterprise victims
CampaignAbout this happening: Webworm is running a multi-country targeting campaign against government agencies and enterprises, expanding the risk of persistent access across several regions. The...
Red Menshen telecom espionage campaign
Campaign
H score33
First: 26.03.2026 19:40
Last: 26.03.2026 19:40
Sources 1
About this happening:
A China-nexus Red Menshen operation has sustained covert access in telecom networks across the Middle East and Asia, increasing the risk of government espion...
Red Menshen telecom espionage campaign
CampaignAbout this happening: A China-nexus Red Menshen operation has sustained covert access in telecom networks across the Middle East and Asia, increasing the risk of government espion...
UNC2814 multi-country cyber espionage campaign
Campaign
H score25
First: 25.02.2026 19:46
Last: 25.02.2026 19:46
Sources 1
About this happening:
The UNC2814 espionage campaign was disrupted after it was tied to breaches at 53 organizations across 42 countries, reducing infrastructure used for long-term access a...
UNC2814 multi-country cyber espionage campaign
CampaignAbout this happening: The UNC2814 espionage campaign was disrupted after it was tied to breaches at 53 organizations across 42 countries, reducing infrastructure used for long-term access a...
Timeline
-
25.06.2026 03:00 3 articles · 21d ago
Unit 42 uncovers CL-STA-1062 campaign targeting Southeast Asian critical infrastructure
Initial DisclosurePalo Alto Networks Unit 42 identified a China-linked campaign by CL-STA-1062 targeting government entities and critical infrastructure in Southeast Asia, including state-owned enterprises in the energy and government sectors. The researchers said the activity had been active since at least March 2022, was observed throughout 2025, and involved the previously undocumented TinyRCT backdoor alongside SoftEther VPN, Mimikatz, and VNT.
Show sources
- China-Linked Hackers Strike Asian Critical Infrastructure with TinyRCT Backdoor — www.infosecurity-magazine.com — 26.06.2026 13:30
- China-Linked Hackers Strike Asian Critical Infrastructure with TinyRCT Backdoor — www.infosecurity-magazine.com — 26.06.2026 13:30
- Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign — thehackernews.com — 26.06.2026 19:21