Adversary Intelligence — 2026-06-27

Chinese APT CL-STA-1062 Deploys New TinyRCT Backdoor Against Southeast Asian Government and Energy Targets

BLUFCoordinated targeting of government and state energy infrastructure in a single country, paired with network mapping and anti-forensic tooling, points to pre-positioning for disruptive access beyond conventional espionage.

Palo Alto Networks Unit 42 published a report June 25 attributing a sustained 2025 campaign against Southeast Asian government and state-owned energy organizations to CL-STA-1062, a Chinese-speaking APT active since at least March 2022 12. At least ten organizations in the region were likely compromised between October and December 2025, including two state-owned energy entities in an unnamed Southeast Asian country 23. The campaign debuted TinyRCT, a previously undocumented C# backdoor with simplified Chinese strings in its code, supporting command execution, file exfiltration, screenshot capture, and self-deletion via hardcoded C2 infrastructure with AES-128 CBC encryption 13. Unit 42 assesses with high confidence that CL-STA-1062 is the same actor Cisco Talos tracks as UAT-7237, previously reported targeting Taiwanese web hosting infrastructure in mid-2025 23.

Analysis
TinyRCT's self-deletion means affected organizations cannot reconstruct what was exfiltrated or how long access persisted, stripping post-compromise attribution. Simultaneous targeting of government and energy entities in a single unnamed country points to coordinated collection against a specific geopolitical objective, not access brokerage. Web server source code exfiltration alongside network reconnaissance marks this as infrastructure mapping consistent with pre-positioning for future access. All sourcing traces to a single Unit 42 primary report with no independent corroboration, which limits confidence in scope claims. The hybrid toolkit combining commercial VPN software with credential-harvesting utilities is equally consistent with a contractor group conducting economic espionage under loose state direction rather than a dedicated collection unit with standing regional tasking.
4 sources
  1. CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure - Palo Alto Networks Unit 42
  2. China-Linked Hackers Strike Asian Critical Infrastructure with TinyRCT Backdoor - Infosecurity Magazine
  3. Chinese APT CL-STA-1062 targets Southeast Asia with new TinyRCT backdoor - SC Media
  4. Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign - The Hacker News

View in full brief →

UNCLASSIFIED // OPEN SOURCE