threat-intel
CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure
High
Summary
Palo Alto Unit 42 has identified a sustained cyber threat campaign, CL-STA-1062, targeting government and critical infrastructure entities in Southeast Asia since at least March 2022. The group, linked to UAT-7237, utilizes a hybrid toolkit including a newly developed backdoor, TinyRCT, to achieve arbitrary command execution and data exfiltration. Recent activity involved compromising multiple organizations, including energy and government sectors, through web shell exploitation and subsequent data theft.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
