China-Linked Hackers Strike Asian Critical Infrastructure with TinyRCT Backdoor

2026-06-26T14:52:14Za2fa8f0bbed468afc59458a353a1b17f5d2a07a600f6b4a398270e8c438aa805
A12A13Apple BootROMChina-linkedCiscoEDR-bypassGentleKillerGentlemen gangMDM-bypassMastraNorth KoreaSD-WANSapphire SleetSoutheast AsiaTinyRCTXPCcritical-infrastructureexploitinfostealer takedown (Operation Endgame) / StealC Amadey removalmacOSnation-stateransomwaresupply-chainunpatchablezero-day

What happened

A broad set of active threats and high-impact incidents were reported: China-linked actors deploying a new TinyRCT backdoor against Southeast Asian critical infrastructure; multiple exploited/zero-day vulnerabilities including a Cisco Catalyst SD‑WAN Manager flaw abused months before disclosure and a macOS XPC bug allowing standard users to disable EDR/MDM; an unpatchable Apple BootROM exploit affecting A12/A13 devices; nation‑state supply‑chain activity (Mastra linked to North Korea) and breaches of tooling/services (Klue) that exposed OAuth tokens and impacted security firms. Threat actor T&

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
a2fa8f0bbed468afc59458a353a1b17f5d2a07a600f6b4a398270e8c438aa805
Enrichment time
2026-06-26T14:52:14Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.