Threats · 76 days ago
This is no longer just a commodity-tool espionage cluster. CL-STA-1062 has added a custom backdoor to a long-running campaign, which means defenders cannot treat the activity as simple script-driven intrusion or rely on commodity-malware detections alone.
Unit 42 ties 2025 intrusions against Southeast Asian government and energy organizations to the cluster, including state-owned enterprises. The group used a hybrid toolkit built around common open-source utilities such as SoftEther VPN, Mimikatz, and VNT, then added TinyRCT, a previously undocumented backdoor that can run commands, enumerate and steal files, capture screens, and delete itself.
The pattern matters because the custom implant gives the operators a quieter way to stay embedded after initial access. In environments that depend on remote access tools and normal admin traffic, that shifts the threat from opportunistic access to sustained espionage with a smaller visible footprint.
4 sources covering this story
China-Linked Group Targets Southeast Asia Critical Systems
The group compromised at least 10 regional organizations, including two state-owned entities, and deployed a new backdoor.
Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign
Unit 42 links CL-STA-1062 to TinyRCT, a custom .NET backdoor used against government and energy targets in Southeast Asia.
China-Linked Hackers Strike Asian CNI with New Backdoor
A China-linked threat group has been targeting critical infrastructure in Southeast Asia with a new custom backdoor called TinyRCT
CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure
Government entities and critical infrastructure were targeted for espionage in SE Asia by attackers using a hybrid toolkit, including custom TinyRCT backdoor.
Part of the PlainSec briefing for 2026-07-01