Chinese Cyber Group Targets Southeast Asian Utilities with New Backdoor
A China-linked group has successfully breached electricity and water providers across Southeast Asia, deploying a previously undocumented backdoor tool built to erase its own tracks.

Key points
- CL-STA-1062 targeted electricity and water providers, plus government and military organizations, across Southeast Asia in 2025.
- The group deploys TinyRCT, a previously undocumented backdoor written in C# that can delete forensic evidence on command.
- Palo Alto Networks has investigated more than 10 attacks by the group.
- Researchers hold high confidence that CL-STA-1062 is the same actor Cisco Talos previously tracked as UAT-7237, targeting Taiwan.
A China-linked group called CL-STA-1062 has successfully breached electricity and water providers in multiple Southeast Asian countries, alongside government and military targets. Palo Alto Networks published its analysis on 25 June, covering more than 10 attacks. Our 26 June story on TinyRCT was first to bring that report to Threat Vectr readers.
The group's central tool is TinyRCT, a lightweight C# remote-access trojan (a program giving attackers hidden control of a compromised machine) that spy on users, execute shell commands, and pull data from infected systems. It's not derived from any known Chinese threat-actor toolset, according to Palo Alto Networks senior vice president Yoni Allon, who told Dark Reading the backdoor is "designed to evade sandboxes and other analysis tools by implementing an array of anti-analysis maneuvers." Operators can trigger a self-destruct command the moment they detect scrutiny.
TinyRCT disguises itself as PerfWatson2.exe, a legitimate Visual Studio component. A second tool used in the same attacks, SoftEther VPN, travels under filenames mimicking VMware executables.
Palo Alto Networks had previously detected the group under a different label. They now assess with high confidence that CL-STA-1062 is the same actor Cisco Talos tracked as UAT-7237, which had concentrated on Taiwanese targets before the pivot to Southeast Asia.
Should customers be worried?
For utility customers, the direct risk isn't espionage of your bill data. Palo Alto Networks confirmed it hasn't observed exfiltration of electricity-related data or malware aimed at operational technology. That finding pushed researchers toward a low-confidence assessment that the group may be an initial access broker: getting inside, mapping the environment, then handing the foothold to a separate operator. One victim was under sustained attack spanning initial entry through data exfiltration, with the group pivoting between government entities in the same country. Others saw the group stop after fingerprinting the network. The pattern's inconsistency is exactly what makes it hard to dismiss.
Allon told Dark Reading the group poses a higher threat than comparable Chinese APT clusters precisely because it's achieving real compromises, not just probing perimeters. In one case, the group conducted vulnerability scanning against a water utility in the same country as a confirmed victim, though Palo Alto Networks couldn't confirm a breach there.
Activity has dropped since late 2025. Allon's framing is worth sitting with: "This could be due to improvements in the group's ability to hide their activity." Less visible doesn't mean less active.



