Palo Alto Networks Unit 42 reported that the Chinese-speaking intrusion cluster CL-STA-1062, assessed with high confidence to overlap with Cisco Talos' UAT-7237, conducted sustained operations across East and Southeast Asia from at least 2022 through 2025. In 2025, the group targeted Southeast Asian government entities and state-owned critical energy infrastructure, using web application exploitation, ASPX web shells, reconnaissance, lateral movement, and data exfiltration to maintain access and steal information.
Investigators said the actors combined open-source tooling including SoftEther VPN, VNT, yuze, Mimikatz, and JuicyPotato with a newly documented custom .NET backdoor, TinyRCT. The malware supports command execution, file listing and exfiltration, screenshot capture, encrypted HTTP-based command-and-control, and a self-destruct feature intended to erase forensic evidence. Unit 42 also reconstructed an infection chain in which a malicious chrome_setup.zip archive used AppDomainManager Injection to load a malicious DLL, download PerfWatson2.exe from attacker infrastructure, and establish persistence through a scheduled task.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Unit 42 said it observed at least 10 organizational breaches in Southeast Asia between October and December 2025 linked to CL-STA-1062. The reporting also described a September 2025 intrusion in which the attackers used a web shell to exfiltrate data from an MS SQL server and stole a directory of web server source code.
In 2025, CL-STA-1062 targeted Southeast Asian government entities and state-owned critical energy infrastructure. The operations involved web application exploitation, ASPX web shells, reconnaissance, lateral movement, and data exfiltration.
Unit 42 reported that the Chinese-speaking activity cluster CL-STA-1062 conducted sustained operations across East and Southeast Asia from at least 2022 through 2025. The group is assessed with high confidence to be the same as Cisco Talos' UAT-7237.
Unit 42 reported an infection chain in which a malicious chrome_setup.zip archive used AppDomainManager Injection to load a malicious DLL, download PerfWatson2.exe from attacker infrastructure, and establish persistence via a scheduled task. The report also noted the actors' use of a hybrid toolkit including SoftEther VPN, VNT, yuze, Mimikatz, and JuicyPotato.
Unit 42 disclosed that the threat cluster used a newly documented custom .NET backdoor called TinyRCT. The malware supports command execution, file listing and exfiltration, screenshot capture, encrypted HTTP-based command-and-control, and a self-destruct routine to remove forensic evidence.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
darkreading.com
Open sourcescworld.com
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourcecommunity.gurucul.com
Open sourceunit42.paloaltonetworks.com
Open sourceblog.talosintelligence.com
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.