Minacce · 91 giorni fa
La novità non è un altro cluster di espionage, ma il salto di qualità: CL-STA-1062 ha smesso di affidarsi solo a tooling comune e ha introdotto un backdoor proprio. Questo cambia il modello difensivo, perché l’attività non si legge più soltanto come uso opportunistico di strumenti noti, ma come operazione sostenuta, con abbastanza investimento da restare nascosta durante accesso, raccolta e pulizia.
Unit 42 collega alla stessa attività campagne del 2025 contro enti governativi e operatori energetici del Sud-est asiatico, con focus su state-owned enterprise e infrastrutture critiche. Il gruppo, di lingua cinese, usa ancora SoftEther VPN, Mimikatz e VNT, ma ha aggiunto TinyRCT: un backdoor non documentato prima, capace di eseguire comandi, enumerare ed esfiltrare file, catturare schermate e autodistruggersi.
Per SOC e incident response il punto non è cercare solo malware commodity. Qui il rischio è confondere traffico e strumenti di amministrazione legittimi con la fase di impianto, e lasciarsi sfuggire un payload custom che si mescola agli accessi normali e poi sparisce.
4 fonti che coprono questa storia
China-Linked Group Targets Southeast Asia Critical Systems
The group compromised at least 10 regional organizations, including two state-owned entities, and deployed a new backdoor.
Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign
Unit 42 links CL-STA-1062 to TinyRCT, a custom .NET backdoor used against government and energy targets in Southeast Asia.
China-Linked Hackers Strike Asian CNI with New Backdoor
A China-linked threat group has been targeting critical infrastructure in Southeast Asia with a new custom backdoor called TinyRCT
CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure
Government entities and critical infrastructure were targeted for espionage in SE Asia by attackers using a hybrid toolkit, including custom TinyRCT backdoor.
Part of the PlainSec briefing for 2026-07-01