logo

CL-STA-1062 Hackers Use TinyRCT Backdoor to Target Southeast Asian Governments

ID: 1125454b-ec28-5aa8-92da-24033abd8a11

STIX ID: report--1125454b-ec28-5aa8-92da-24033abd8a11

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-06-26

Date Updated: 2026-06-26

Author: Tushar Subhra Dutta

...
...

Unit 42 and related reporting attribute an ongoing Southeast Asia campaign to a Chinese-speaking group called CL-STA-1062 (also tracked as UAT-7237), which since at least March 2022 — and intensifying in late 2025 — has targeted government and energy organizations using freely available tools (SoftEther, Mimikatz, JuicyPotato) alongside a custom C# backdoor named TinyRCT delivered via a malicious chrome_setup.zip; the report provides TTPs, remediation hints, and detailed IoCs (file hashes, C2 IPs/URLs, filenames).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.