Security News

Cybersecurity news aggregator

HIGH Attacks SC Media

Chinese APT CL-STA-1062 targets Southeast Asia with new TinyRCT backdoor

The Chinese APT group CL-STA-1062 is targeting Southeast Asian government and energy sectors using a new custom backdoor called TinyRCT. Initial access is gained via ASPX web shells on vulnerable web applications, followed by deployment of a hybrid toolkit including the TinyRCT backdoor for command execution and data exfiltration. The group establishes persistence through VPNs and legitimate-looking processes, with continued activity expected against these sectors.
Read Full Article →

Threat Intelligence Chinese APT CL-STA-1062 targets Southeast Asia with new TinyRCT backdoor June 26, 2026 Share By SC Staff (Adobe Stock) A Chinese-speaking threat actor, identified as CL-STA-1062, has been actively conducting persistent operations in East Asia since March 2022, with a recent focus on government and critical energy infrastructure in Southeast Asia starting mid-2025, according to a report by Palo Alto Networks Unit 42. This group, previously known as UAT-7237, has been observed breaching at least 10 organizations in the region between October and December 2025, based on information published by Security Affairs. CL-STA-1062 employs a hybrid toolkit, combining open-source tools like SoftEther VPN, Mimikatz, and VNT with a newly discovered custom backdoor named TinyRCT. Initial access is gained through ASPX web shells exploiting vulnerable web applications. The attackers then establish persistence using VPNs and other tools disguised as legitimate system processes. TinyRCT, a lightweight C# backdoor, allows for arbitrary command execution, file exfiltration, screenshot capture, and self-deletion, with its code containing a simplified Chinese string indicating its origin. The malware uses hardcoded C2 addresses and AES-128 CBC encryption. Delivery often involves a malicious DLL disguised within a seemingly legitimate application installer. The group has been observed exfiltrating data, including web server source code, and conducting network reconnaissance to identify lateral movement opportunities. Attackers also leverage tools like JuicyPotato for privilege escalation, compressing exfiltrated data into password-protected RAR archives. Palo Alto Networks Unit 42 assesses that these activities will continue, with Southeast Asian energy and government organizations remaining primary targets. Source: Security Affairs SC Staff Related Threat Intelligence Turla group deploys new STOCKSTAY backdoor against Ukraine and Italy SC Staff June 26, 2026 STOCKSTAY, written in .NET and utilizing the Windows Forms framework, communicates with its command-and-control (C2) server via a secure WebSocket connection. Threat Intelligence Russian hackers suspected in Jaguar Land Rover cyberattack SC Staff June 26, 2026 The cyberattack on Jaguar Land Rover (JLR), a major UK employer, caused production to halt for months, resulting in an estimated $2.5 billion loss to the British economy and necessitating a £1.5 billion government bailout. Threat Intelligence Sports piracy ring linked to PirloTV disrupted in 44-domain takedown SC Staff June 25, 2026 The Alliance for Creativity and Entertainment (ACE), in collaboration with UEFA, UC3, and Mexican authorities, successfully shut down 44 domains linked to PirloTV. Related Events Cybercast Better Threat Intelligence Between Public and Private Sectors On-Demand Event Virtual Conference Nationwide Cybersecurity Summit 2025: Safeguarding America’s Digital Future On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Account Harvesting DNS Spoofing Deauthentication Attack Defacement Dictionary Attack Distributed Scans Domain Hijacking Google Hacking Information Warfare Reconnaissance You can skip this ad in 5 seconds

Share this article