CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure with TinyRCT Backdoor
Unit 42 identifies a Chinese-speaking threat actor targeting government entities and critical infrastructure in Southeast Asia with a custom backdoor named TinyRCT.

Unit 42 has identified a threat actor tracked as CL-STA-1062 targeting government entities and critical infrastructure in Southeast Asia for espionage. The attackers deploy a hybrid toolkit that includes a custom backdoor named TinyRCT. The campaign leverages custom malware to compromise high-value targets in the region.
Throughout 2025, Unit 42 observed a cluster of activity targeting government entities and critical infrastructure in Southeast Asia, specifically state-owned enterprises in the energy and government sectors. The Chinese-speaking attackers behind this cluster, tracked as CL-STA-1062, have been active since at least March 2022. Unit 42 assesses with high confidence that this is the same cluster known as UAT-7237, previously reported for campaigns against web hosting infrastructure in Taiwan in mid-2025. Earlier operations also targeted strategic sectors in East Asia, indicating a broader, sustained regional focus.
From a technical standpoint, the attackers rely on a hybrid toolkit. While they frequently use common open-source tools such as SoftEther VPN, Mimikatz, and VNT, they have recently introduced TinyRCT, a bespoke, previously undocumented backdoor. TinyRCT's capabilities include arbitrary command execution, file enumeration and exfiltration, screen capture, and a self-destruct mechanism.
In September 2025, Unit 42 discovered that CL-STA-1062 had compromised a Southeast Asian government entity by deploying web shells and exfiltrating database information. The attackers also conducted network reconnaissance on a separate government entity in the same country, suggesting efforts to identify lateral movement opportunities. Between October and December 2025, Unit 42 observed the likely compromise of at least ten different organizations in Southeast Asia.
Since mid-2025, the threat actor focused on critical infrastructure. Unit 42 identified that a critical infrastructure entity had been under attack for several months, with activity covering the entire attack lifecycle from initial access to data exfiltration. The following month, two state-owned critical energy infrastructure entities in the same Southeast Asian country were compromised. Attackers scanned for vulnerabilities, followed by outbound requests to attacker-controlled infrastructure, downloading SoftEther VPN components and RAR archives containing tools.
The intrusions typically begin with exploiting web applications to deploy ASPX web shells, which serve as the central mechanism for executing arbitrary commands, dropping additional tooling, and conducting initial reconnaissance. The attackers frequently use tunneling tools for command and control and data exfiltration, including SoftEther VPN, yuze, and VNT, often disguised as legitimate system files such as VMware executables or XDR agents.
Palo Alto Networks customers are protected through Cortex XDR and XSIAM, Advanced WildFire, and Advanced URL Filtering and Advanced DNS Security. Organizations in Southeast Asia should remain vigilant and implement robust detection and response measures to defend against this persistent threat.
The new report, released by Unit 42 on June 26, 2026, provides additional technical granularity on TinyRCT's delivery mechanism: the malware is distributed via a malicious archive called chrome_setup.zip that leverages AppDomainManager Injection to load a hidden DLL within a legitimate Chrome installer process. The article also reveals that at least ten organizations were compromised between October and December 2025, including two state-owned energy firms, and that the group used a self-destruct routine that employs choice.exe to delay file deletion. Furthermore, the report names 24 specific indicators of compromise spanning SHA256 hashes, IP addresses, and URLs, giving defenders precise artifacts to hunt for within their networks.
Unit 42's latest report, published on June 25, provides deeper technical analysis of the TinyRCT backdoor, revealing its self-destruct mechanism and screenshot capture capabilities. The researchers assessed with high confidence that CL-STA-1062 is the same group tracked by Cisco Talos as UAT-7237, which targeted web hosting infrastructure in Taiwan in mid-2025. Between October and December 2025, at least ten organizations across Southeast Asia were likely compromised, including three critical infrastructure entities in an unnamed country.
The Hacker News carried additional details from the same Unit 42 report, noting that CL-STA-1062 has been active since at least March 2022 and has recently targeted state-owned enterprises in the energy and government sectors. Palo Alto Networks linked TinyRCT, a lightweight RAT that encrypts C2 traffic with AES-128, to the group, and reported breaching at least 10 organizations in the region between October and December 2025. The delivery chain involves a malicious chrome_setup.zip archive containing an AppDomainManager injection DLL that downloads the backdoor from a separate server.
This new report from Dark Reading indicates that the China-linked threat group has expanded its targeting to at least 10 organizations in Southeast Asia, including two state-owned entities. The campaign involves the deployment of a previously unmentioned new backdoor, suggesting an evolving toolkit or a distinct operation within the broader campaign.