China-Linked Hackers Strike Asian Critical Infrastructure with TinyRCT Backdoor
2026-06-26T14:52:14Z•a2fa8f0bbed468afc59458a353a1b17f5d2a07a600f6b4a398270e8c438aa805
A12A13Apple BootROMChina-linkedCiscoEDR-bypassGentleKillerGentlemen gangMDM-bypassMastraNorth KoreaSD-WANSapphire SleetSoutheast AsiaTinyRCTXPCcritical-infrastructureexploitinfostealer takedown (Operation Endgame) / StealC Amadey removalmacOSnation-stateransomwaresupply-chainunpatchablezero-day
What happened
A broad set of active threats and high-impact incidents were reported: China-linked actors deploying a new TinyRCT backdoor against Southeast Asian critical infrastructure; multiple exploited/zero-day vulnerabilities including a Cisco Catalyst SD‑WAN Manager flaw abused months before disclosure and a macOS XPC bug allowing standard users to disable EDR/MDM; an unpatchable Apple BootROM exploit affecting A12/A13 devices; nation‑state supply‑chain activity (Mastra linked to North Korea) and breaches of tooling/services (Klue) that exposed OAuth tokens and impacted security firms. Threat actor T&
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- a2fa8f0bbed468afc59458a353a1b17f5d2a07a600f6b4a398270e8c438aa805
- Enrichment time
- 2026-06-26T14:52:14Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.