A Chinese-speaking threat actor known as CL-STA-1062 is targeting government and energy sectors in Southeast Asia using a custom backdoor called TinyRCT to exfiltrate sensitive data.
Key Points
- Palo Alto Networks Unit 42 identified CL-STA-1062, a group linked to at least 10 organizational breaches between October and December 2025.
- The group utilizes TinyRCT, a previously undocumented .NET backdoor capable of remote command execution, file exfiltration, and screen capture.
- Attackers gain initial access by deploying ASPX web shells and using AppDomainManager injection techniques disguised as legitimate software like Google Chrome.
- The threat actor employs a hybrid toolkit, combining custom malware with open-source utilities such as SoftEther VPN, Mimikatz, and the Yuze SOCKS5 proxy.
- Operations involve scanning critical infrastructure for vulnerabilities to facilitate lateral movement and long-term persistence within compromised government networks.