unit42 · Crawled Jul 5, 2026
CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure
13 IoCs 1 Actors 2 Malware
Read original article ↗
AI Summary
CL-STA-1062, a Chinese-speaking threat actor group active since at least March 2022, has been targeting government entities and critical infrastructure in Southeast Asia. The group, also tracked as UAT-7237, uses a hybrid toolkit combining open-source tools like SoftEther VPN, Mimikatz, and VNT with a custom backdoor named TinyRCT. This backdoor enables command execution, file exfiltration, screen capture, and self-destruction, and is deployed via AppDomainManager injection through a maliciously crafted archive. The campaign demonstrates a sustained regional focus, with attacks spanning from Taiwan to Southeast Asia, particularly targeting energy and government sectors.
AI-extracted · verify before operational use
Extracted Entities 3 found
Indicators of Compromise 13 extracted
| Type | Value | Detail |
|---|---|---|
| IP | 139[.]180[.]134[.]221 | Details → |
| IP | 202[.]182[.]102[.]5 | Details → |
| IP | 45[.]76[.]210[.]43 | Details → |
| IP | 45[.]32[.]113[.]172 | Details → |
| SHA-256 | 00e09754526d0fe836ba27e3144ae161b0ecd3774abec5560504a16a67f0087c | Details → |
| SHA-256 | f34bd1d485de437fe18360d1e850c3fd64415e49d691e610711d8d232071a0b1 | Details → |
| SHA-256 | dce5df29bddff5a4ddaea5c4fec14da91f7b69063a6e1c45ed61e5da4fc6c87b | Details → |
| SHA-256 | cbfe8de6ffadbb1d396f61e63eb18e8b11c29527c1528641e3223d4c516cf7c3 | Details → |
| SHA-256 | 4e1f8888d020decd09799ec946f1bf677cac6612b24582ddbf4d8ede425d8384 | Details → |
| SHA-256 | 9b481b69cd91b09fa7bae7428f646dd89473a4c03393e43da81fe756cde1c472 | Details → |
| Filename | PerfWatson2.exe | Details → |
| Filename | MyAppDomainManager.dll | Details → |
| Filename | chrome_setup.zip | Details → |
MITRE ATT&CK TTPs 72 techniques
T1003 OS Credential Dumping · Credential Access T1021 Remote Services · Lateral Movement T1055.003 Thread Execution Hijacking · Defense Evasion T1059.001 PowerShell · Execution T1071.001 Web Protocols · Command And Control T1074 Data Staged · Collection T1082 System Information Discovery · Discovery T1110 Brute Force · Credential Access T1212 Exploitation for Credential Access · Credential Access T1485 Data Destruction · Impact T1001.001 Junk Data · Command And Control T1003.001 LSASS Memory · Credential Access T1003.002 Security Account Manager · Credential Access T1018 Remote System Discovery · Discovery T1021.001 Remote Desktop Protocol · Lateral Movement T1021.002 SMB/Windows Admin Shares · Lateral Movement T1021.003 Distributed Component Object Model · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1033 System Owner/User Discovery · Discovery T1046 Network Service Discovery · Discovery T1048 Exfiltration Over Alternative Protocol · Exfiltration T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol · Exfiltration T1053 Scheduled Task/Job · Execution T1053.005 Scheduled Task · Execution T1055 Process Injection · Defense Evasion T1057 Process Discovery · Discovery T1070.001 Clear Windows Event Logs · Defense Evasion T1070.004 File Deletion · Defense Evasion T1071.003 Mail Protocols · Command And Control T1074.001 Local Data Staging · Collection T1078 Valid Accounts · Defense Evasion T1078.001 Default Accounts · Defense Evasion T1083 File and Directory Discovery · Discovery T1086 T1086 T1087.001 Local Account · Discovery T1087.002 Domain Account · Discovery T1090.001 Internal Proxy · Command And Control T1090.003 Multi-hop Proxy · Command And Control T1098 Account Manipulation · Persistence T1098.001 Additional Cloud Credentials · Persistence T1105 Ingress Tool Transfer · Command And Control T1110.003 Password Spraying · Credential Access T1112 Modify Registry · Defense Evasion T1114 Email Collection · Collection T1129 Shared Modules · Execution T1133 External Remote Services · Persistence T1140 Deobfuscate/Decode Files or Information · Defense Evasion T1204.002 Malicious File · Execution T1210 Exploitation of Remote Services · Lateral Movement T1222 File and Directory Permissions Modification · Defense Evasion T1222.001 Windows File and Directory Permissions Modification · Defense Evasion T1482 Domain Trust Discovery · Discovery T1484 Domain or Tenant Policy Modification · Defense Evasion T1484.001 Group Policy Modification · Defense Evasion T1486 Data Encrypted for Impact · Impact T1489 Service Stop · Impact T1490 Inhibit System Recovery · Impact T1537 Transfer Data to Cloud Account · Exfiltration T1543.003 Windows Service · Persistence T1547.001 Registry Run Keys / Startup Folder · Persistence T1558.003 Kerberoasting · Credential Access T1562.001 Disable or Modify Tools · Defense Evasion T1566 Phishing · Initial Access T1569.002 Service Execution · Execution T1570 Lateral Tool Transfer · Lateral Movement T1571 Non-Standard Port · Command And Control T1572 Protocol Tunneling · Command And Control T1573 Encrypted Channel · Command And Control T1573.001 Symmetric Cryptography · Command And Control T1574 Hijack Execution Flow · Persistence T1589 Gather Victim Identity Information · Reconnaissance T1614 System Location Discovery · Discovery