CL-STA-1062 Hackers Use TinyRCT Backdoor to Target Southeast Asian Governments
ID: 1125454b-ec28-5aa8-92da-24033abd8a11
STIX ID: report--1125454b-ec28-5aa8-92da-24033abd8a11
Feed Name: cybersecurityNews.com
Unit 42 and related reporting attribute an ongoing Southeast Asia campaign to a Chinese-speaking group called CL-STA-1062 (also tracked as UAT-7237), which since at least March 2022 — and intensifying in late 2025 — has targeted government and energy organizations using freely available tools (SoftEther, Mimikatz, JuicyPotato) alongside a custom C# backdoor named TinyRCT delivered via a malicious chrome_setup.zip; the report provides TTPs, remediation hints, and detailed IoCs (file hashes, C2 IPs/URLs, filenames).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
