CL-STA-1062 is a Chinese-speaking espionage threat cluster assessed with high confidence to overlap with UAT-7237. The actor has conducted persistent operations across East Asia since at least March 2022 and, from mid-2025 onward, shifted significant focus to Southeast Asian government entities and state-owned critical infrastructure, particularly energy providers. Earlier activity linked to the same cluster targeted web-hosting infrastructure in Taiwan. The group typically gains initial access by exploiting vulnerable web applications and deploying ASPX web shells. After compromise, it conducts reconnaissance, establishes persistence, and uses tunneling and remote-access tooling to maintain access and move within victim environments. Observed tooling includes open-source utilities such as SoftEther VPN, VNT, Yuze, Mimikatz, and JuicyPotato, alongside a custom C# backdoor known as TinyRCT. TinyRCT supports remote command execution, system and file enumeration, screenshot capture, file theft, encrypted command-and-control over HTTP, and self-deletion. The actor has also used DLL side-loading and process masquerading to blend malicious components with legitimate software and evade detection. Operations attributed to CL-STA-1062 have included credential theft, privilege escalation, lateral movement between related government entities, long-term persistence in critical infrastructure networks, and exfiltration of sensitive data including database contents and web server source code. In some intrusions the activity appeared to stop after access establishment and environment fingerprinting, while in others the actor sustained multi-month campaigns through post-exploitation and data theft. The targeting pattern, victimology, and operational behavior are consistent with intelligence collection against government and strategic infrastructure in Southeast Asia.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
35 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
19 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-linked espionage or possible initial-access activity targeting Southeast Asian critical infrastructure, government, and military organizations, using a novel backdoor and lateral movement across linked entities.
Persistent intrusion operations in East Asia, recently focused on government and critical energy infrastructure in Southeast Asia, involving breaches, data exfiltration, reconnaissance, persistence, and lateral movement preparation.
Persistent espionage-oriented intrusions across East Asia, with a later focus on Southeast Asian government entities and state-owned critical energy infrastructure. The group uses web shells, open-source post-exploitation tools, tunneling utilities, and the custom TinyRCT backdoor for persistence, reconnaissance, lateral movement, and data exfiltration.
Espionage-oriented intrusions targeting government entities, state-owned enterprises, and critical infrastructure in Southeast Asia and East Asia, using a hybrid toolkit of open-source utilities and the custom TinyRCT backdoor for reconnaissance, persistence, lateral movement, and data exfiltration.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.