All incidents

Chinese APT CL-STA-1062 uses TinyRCT backdoor on Southeast Asian energy targets

campaignclosedJun 26, 2026 — Jul 1, 2026
Chinese APT CL-STA-1062 uses TinyRCT backdoor on Southeast Asian energy targets

A China‑linked threat group tracked as CL‑STA‑1062 has been observed deploying a new backdoor called TinyRCT against energy, water and government organisations across Southeast Asia. The activity was highlighted by Dark Reading here.

TinyRCT is a compact stealthy backdoor that gives attackers the ability to run arbitrary commands, steal data and erase its traces with a built‑in self‑destruct function. Unit 42 describes the tool in detail here.

The group gains initial footholds by exploiting web application vulnerabilities and planting ASPX web shells, then relies on open‑source tunneling tools such as SoftEther VPN and credential dumpers like Mimikatz to move laterally. SecurityOnline notes this tactic here.

Activity was first seen on 26 June 2026 and continued through early July, with at least ten confirmed victims in the region. SecurityAffairs reports the timeline here.

Defenders should search for unusual outbound TLS connections to unfamiliar endpoints, review web server logs for unfamiliar ASPX files and enforce strict application control to block unknown executables. Infosecurity Magazine offers these recommendations here.

Keeping web applications patched, disabling unnecessary services and using network segmentation to isolate critical OT environments will limit the group’s ability to persist and move laterally. Unit 42 points out these mitigations here.

Intelligence briefing updated Jul 1, 2026

CL-STA-1062
Root sourceunit42.paloaltonetworks.com
Timeline Coverage

Swipe to explore timeline