Security News

Cybersecurity news aggregator

HIGH Attacks Dark Reading

China-Linked Group Targets Southeast Asia Critical Systems

A China-linked threat group, CL-STA-1062, has successfully compromised at least ten critical infrastructure providers and government organizations in Southeast Asia using lateral movement and a new backdoor dubbed TinyRCT. The group's primary attack vector involves targeting electricity and water utilities, moving from initial compromises to scan and potentially breach related entities within the same country. This activity represents an escalation from previous espionage-focused operations to pre-positioning within critical systems.
Read Full Article →

Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources THREAT INTELLIGENCE CYBER RISK VULNERABILITIES & THREATS CYBERATTACKS & DATA BREACHES NEWS Breaking cybersecurity news, news analysis, commentary, and other content from around the world, with an initial focus on the Middle East & Africa and the Asia Pacific China-Linked Group Targets Southeast Asia Critical Systems The group compromised at least 10 regional organizations, including two state-owned entities, and deployed a new backdoor. Robert Lemos,Contributing Writer July 1, 2026 4 Min Read Gas-fired power plant in ThailandSOURCE: DIFFERR VIA SHUTTERSTOCK A China-linked cyberthreat group, CL-STA-1062, has moved from attacking Web-hosting infrastructure in Taiwan to successfully targeting critical-infrastructure providers in Southeast Asia over the past year, cybersecurity researchers say. The group has successfully targeted electricity and water providers in multiple countries as well as several government and military organizations across the region, deploying a new backdoor tool dubbed TinyRCT, researchers with cybersecurity firm Palo Alto Networks said in a report published last week. Overall, Palo Alto Networks has investigated more than 10 attacks by the group targeting Southeast Asian organizations, the company stated in its June 25 analysis. The group has used lateral movement to target multiple government agencies or linked organizations in the same country, says Yoni Allon, senior vice president of software engineering at Palo Alto Networks. Related:Local Police Collusion Hampers Crackdown on Asian Scam Centers "The main reason that we consider that the group poses a higher threat than other similar Chinese APT groups is that they are successfully compromising critical infrastructure providers," he says. "In one case, we saw them conducting vulnerability scanning against a water utility in the same country, but we were unable to determine whether they were successful in compromising this victim." China has escalated cyberattacks in the Southeast Asian region over the past decade. Researchers previously detected cyber-espionage operations in military and government networks in the region that linked to activity stretching back to 2020. Over the same time, China shifted from pure espionage activity to a long-term plan of pre-positioned compromises, preparing for future possible conflicts, as seen in the operations connected to Volt Typhoon. The latest operations come from a Chinese-language group that Palo Alto Network's Unit 42 researchers call CL-STA-1062. The group is very likely the same as a previous group detected by Cisco Talos researchers known as UAT-7237, which had targeted Taiwanese targets. Palo Alto Networks did not name the countries impacted by CL-STA-1062's attacks, but said they had high confidence the two groups were the same actor. Cisco declined to be interviewed for this article. TinyRCT: A First Look A significant change, however, is that CL-STA-1062 now deploys a novel backdoor tool, known as TinyRCT. The researchers first detected the implant in 2025, describing it as small and stealthy with anti-analysis features, including a self-destruct mechanism that aims to delete forensic evidence. The backdoor is designed to aid in spying on the system's users and allowing remote management and command execution via the shell, configuration updates, and a variety of system fingerprinting and data exfiltration. Related:China Uses Dual-Method Cyberattack on Czech Orgs "After a thorough analysis of the tool, we concluded that it's not a branch of any known tool, nor does it have significant code similarities with any other tools used by the Chinese APT nexus," says Allon, adding that it's "designed to evade sandboxes and other analysis tools by implementing an array of anti-analysis maneuvers, [and] the operators can send a self-destruction command if there's a sign of detection or active investigation." TinyRCT is a lightweight C# remote-access Trojan (RAT) that runs arbitrary commands, with a comment in the C2-parsing code written in simplified Chinese. The backdoor and other components use file names similar to common system components to escape notice. TinyRCT masquerades as PerfWatson2.exe — a real Visual Studio telemetry component, while another tool used in the attacks — SoftEther VPN — uses binaries renamed to resemble VMware executables or an extended detection and response (XDR) agent. Espionage Group or Initial Access Broker Whether the threat group is a cog in an espionage machine or a group that executes an end-to-end operation is unclear, PAN's Unit 42 researchers say. One victim had been under attack for many months, and the attack chains spanned initial access to exfiltration, and pivoted from one government entity toward another in the same country. Yet, in other cases, the CL-STA-1062 group stopped after gaining access and fingerprinting the local environment, Allon says. Related:Chinese APTs Share Linux Backdoor in Central Asia Telco Attacks "We did not observe the exfiltration of any electricity-related data or any malware related to electricity systems or operational technologies more broadly," he says. "This contributed to our low confidence assessment that CL-STA-1062 may be an initial access broker, establishing a foothold in these victims to then be passed on to another group." So far this year, the Palo Alto Networks' researchers have observed continued operations, and in one case, additional tools were deployed against a critical infrastructure victim to aid in persistence, Allon says. Overall, however, the level of activity has dropped, he says. "We have not observed the same volume of new compromises that we saw in late 2025," he says. While the lack of observable activity could indicate that the group has reduced its level of operations, it could also mean they have improved their ability to remain undetected. Allon adds, "This could be due to improvements in the group's ability to hide their activity." Read more about: DR Global Asia Pacific About the Author Robert Lemos Contributing Writer Rob is an award-winning, veteran technology journalist of more than 30 years, reporting on global cybersecurity issues, the latest offensive and defensive technologies, malware incidents, cyber conflict, and AI's impact on software and cybersecurity. A former research engineer, Rob has written for more than two dozen publications, including CNET News.com, Dark Reading, MIT's Technology Review, Popular Science, and Wired News. He has received five awards for journalism, including Best Deadline Journalism (Online) in 2003 for his coverage of the Blaster worm. Rob also analyzes data on various trends using Python and R for both his reporting and his clients. Recent reports include analyses of the shortage in cybersecurity workers, annual vulnerability trends, and annual threat reports. Rob holds degrees from Cornell University in Electrical Engineering and Computer Science (double major). Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges The total economic impact™ of Snyk How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Access More Research Webinars Practical Zero Trust Implementation on a Budget in the Age of Mythos Building a Risk Based Vulnerability Management Program Threat Hunting That Gets Big Results Despite Small Budgets Say Yes to AI: Securing Innovation Without Compromise Zero Trust Identity: Beyond Traditional Authentication More Webinars You May Also Like THREAT INTELLIGENCE Hackers Target Cybersecurity Firm Outpost24 in 7-Stage Phish by Jai Vijayan MAR 17, 2026 THREAT INTELLIGENCE Iran's Cyber-Kinetic War Doctrine Takes Shape by Alexander Culafi MAR 06, 2026 THREAT INTELLIGENCE React2Shell Exploits Flood the Internet as Attacks Continue by Rob Wright DEC 12, 2025 THREAT INTELLIGENCE Chinese Gov't Fronts Trick the West to Obtain Cyber Tech by Nate Nelson, Contributing Writer OCT 06, 2025 Editor's Choice CYBERSECURITY OPERATIONS Do CISOs Need a Code of Ethics? byDark Reading Editorial Team JUN 24, 2026 CYBERSECURITY OPERATIONS 2026 FIFA World Cup Faces Surge in Cyber Threats byAlexander Culafi JUN 24, 2026 3 MIN READ CYBERSECURITY OPERATIONS EU Gets a Head Start in Developing 6G Network Security byNate Nelson JUN 18, 2026 4 MIN READ Want more Dark Reading stories in your Google search results? Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox. SUBSCRIBE AUG 1-6 | MANDALAY BAY, LAS VEGAS USE CODE: DARKREADING & SAVE $200 ON A BRIEFINGS PASS OR $100 ON A BUSINESS PASS The premier cybersecurity event returns. GET YOUR PASS Discover More Black Hat Omdia Working With Us About Us Meet the Editors Advertise Reprints Join Us NEWSLETTER SIGN-UP Follow Us Copyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s registered office is 275 Grove St. Newton, MA 02466. Home| Cookie Policy| Privacy| Terms of Use Your Privacy Choices

Share this article