Palo Alto Networks’ Unit 42 discovered a major cyber espionage campaign targeting critical infrastructure in Southeast Asia.

The threat actor CL-STA-1062 used a previously undocumented backdoor named TinyRCT to infiltrate two state-owned energy companies.

These sustained intrusions have been active since mid-2025. The campaign involves the full attack lifecycle, including initial scanning, compromise, and data exfiltration.

This discovery highlights Palo Alto Networks' capabilities in identifying sophisticated threats for its enterprise customer base.