Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
state-sponsored-espionagegovernment-diplomatic-threatcritical-infrastructure-threatremote-access-implant

Chinese-Speaking CL-STA-1062 Used TinyRCT to Breach Southeast Asian Governments

Updated 13m agoFirst seen Jun 25, 20266 sources

Palo Alto Networks Unit 42 reported that the Chinese-speaking intrusion cluster CL-STA-1062, assessed with high confidence to overlap with Cisco Talos' UAT-7237, conducted sustained operations across East and Southeast Asia from at least 2022 through 2025. In 2025, the group targeted Southeast Asian government entities and state-owned critical energy infrastructure, using web application exploitation, ASPX web shells, reconnaissance, lateral movement, and data exfiltration to maintain access and steal information.

Investigators said the actors combined open-source tooling including SoftEther VPN, VNT, yuze, Mimikatz, and JuicyPotato with a newly documented custom .NET backdoor, TinyRCT. The malware supports command execution, file listing and exfiltration, screenshot capture, encrypted HTTP-based command-and-control, and a self-destruct feature intended to erase forensic evidence. Unit 42 also reconstructed an infection chain in which a malicious chrome_setup.zip archive used AppDomainManager Injection to load a malicious DLL, download PerfWatson2.exe from attacker infrastructure, and establish persistence through a scheduled task.

Share:
Chinese-Speaking CL-STA-1062 Used TinyRCT to Breach Southeast Asian Governments
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Jun 26, 20268h ago

Unit 42 reports 10 CL-STA-1062 breaches in Southeast Asia

Unit 42 said it observed at least 10 organizational breaches in Southeast Asia between October and December 2025 linked to CL-STA-1062. The reporting also described a September 2025 intrusion in which the attackers used a web shell to exfiltrate data from an MS SQL server and stole a directory of web server source code.

Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign
Jun 25, 20261d ago

CL-STA-1062 targets Southeast Asian governments and energy infrastructure

In 2025, CL-STA-1062 targeted Southeast Asian government entities and state-owned critical energy infrastructure. The operations involved web application exploitation, ASPX web shells, reconnaissance, lateral movement, and data exfiltration.

CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure

CL-STA-1062 begins sustained operations in East and Southeast Asia

Unit 42 reported that the Chinese-speaking activity cluster CL-STA-1062 conducted sustained operations across East and Southeast Asia from at least 2022 through 2025. The group is assessed with high confidence to be the same as Cisco Talos' UAT-7237.

CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure

Unit 42 reconstructs TinyRCT infection chain

Unit 42 reported an infection chain in which a malicious chrome_setup.zip archive used AppDomainManager Injection to load a malicious DLL, download PerfWatson2.exe from attacker infrastructure, and establish persistence via a scheduled task. The report also noted the actors' use of a hybrid toolkit including SoftEther VPN, VNT, yuze, Mimikatz, and JuicyPotato.

CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure

Unit 42 documents TinyRCT backdoor used by CL-STA-1062

Unit 42 disclosed that the threat cluster used a newly documented custom .NET backdoor called TinyRCT. The malware supports command execution, file listing and exfiltration, screenshot capture, encrypted HTTP-based command-and-control, and a self-destruct routine to remove forensic evidence.

CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

18 LINKEDOpen in app
Threat actors
1 linked
Affected products
3 linked
WindowsAspnetAnydesk
Organizations
10 linked
Palo Alto NetworksSecurity AffairsCisco SystemsBroadcomGoogleMicrosoft CorporationLinkedinXCyber Security NewsGurucul
Breaches
1 linked
UNNAMEDSOUTHEASTASIANGOVERNMENTENTITY-2025-09
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Chinese-Speaking CL-STA-1062 Used TinyRCT to Breach Southeast Asian Governments | Mallory