CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure

2026-06-26T08:51:40Z313568abb460107a968e4e2764bde10c34e3bc7a68cc9daca44ea8e523a47584
agentic-fraudai-supply-chainbackdoorbucket-squattingclawhubcloud-bucket-hijackingcloud-loggingcredential-attackscve-2026-0257defense-evasionespionagefluttershellinfostealermacosnpm-supply-chainopenclawpan-osremote-code-executionsoutheast-asiatinyrctvertex-ai

What happened

Unit 42 published multiple advisories and research covering high-impact threats: an espionage campaign (CL-STA-1062) using a TinyRCT backdoor targeting Southeast Asian governments and critical infrastructure; AI supply-chain and skill-marketplace abuse (OpenClaw/ClawHub) delivering infostealers and agentic financial fraud; cloud risks including universal bucket hijacking and bucket-squatting leading to cross-tenant RCE in Vertex AI via the Python SDK; abuse of cloud logging for defense evasion; active exploitation of PAN-OS CVE-2026-0257; large-scale credential attack guidance; macOS malvertis

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
paloalto_unit42
Record identifier
313568abb460107a968e4e2764bde10c34e3bc7a68cc9daca44ea8e523a47584
Enrichment time
2026-06-26T08:51:40Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.