CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure
Throughout 2025, Chinese-speaking threat actors tracked as CL-STA-1062 conducted extensive operations against government entities and critical infrastructure in Southeast Asia, specifically targeting state-owned enterprises in energy and government sectors. Active since March 2022, this cluster was previously identified as UAT-7237 in campaigns against Taiwan's web hosting infrastructure. The attackers employ a hybrid toolkit combining open-source tools like SoftEther VPN, Mimikatz, and VNT with a newly discovered custom backdoor called TinyRCT. This .NET-based backdoor provides capabilities including arbitrary command execution, file enumeration and exfiltration, screen capture, and self-destruct mechanisms. The infection chain typically begins with web application exploitation deploying ASPX web shells, followed by credential dumping, lateral movement, and data exfiltration. Between October and December 2025, at least ten organizations across Southeast Asia were compromised, demonstrating sustained regio...
Pulse ID: 6a3db58dcad7fa34b60b3689
Pulse Link: https://otx.alienvault.com/pulse/6a3db58dcad7fa34b60b3689
Pulse Author: AlienVault
Created: 2026-06-25 23:11:09
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #Chinese #CyberSecurity #ELF #Government #InfoSec #NET #OTX #OpenThreatExchange #RAT #RCE #SMS #VPN #bot #stateowned #AlienVault






