Breaking cybersecurity news, news analysis, commentary, and other content from around the world, with an initial focus on the Middle East & Africa and the Asia Pacific

The group compromised at least 10 regional organizations, including two state-owned entities, and deployed a new backdoor.

July 1, 2026

A China-linked cyberthreat group, CL-STA-1062, has moved from attacking Web-hosting infrastructure in Taiwan to successfully targeting critical-infrastructure providers in Southeast Asia over the past year, cybersecurity researchers say.

The group has successfully targeted electricity and water providers in multiple countries as well as several government and military organizations across the region, deploying a new backdoor tool dubbed TinyRCT, researchers with cybersecurity firm Palo Alto Networks said in a report published last week. Overall, Palo Alto Networks has investigated more than 10 attacks by the group targeting Southeast Asian organizations, the company stated in its June 25 analysis.