CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure
2026-06-26T08:51:40Z•313568abb460107a968e4e2764bde10c34e3bc7a68cc9daca44ea8e523a47584
agentic-fraudai-supply-chainbackdoorbucket-squattingclawhubcloud-bucket-hijackingcloud-loggingcredential-attackscve-2026-0257defense-evasionespionagefluttershellinfostealermacosnpm-supply-chainopenclawpan-osremote-code-executionsoutheast-asiatinyrctvertex-ai
What happened
Unit 42 published multiple advisories and research covering high-impact threats: an espionage campaign (CL-STA-1062) using a TinyRCT backdoor targeting Southeast Asian governments and critical infrastructure; AI supply-chain and skill-marketplace abuse (OpenClaw/ClawHub) delivering infostealers and agentic financial fraud; cloud risks including universal bucket hijacking and bucket-squatting leading to cross-tenant RCE in Vertex AI via the Python SDK; abuse of cloud logging for defense evasion; active exploitation of PAN-OS CVE-2026-0257; large-scale credential attack guidance; macOS malvertis
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- paloalto_unit42
- Record identifier
- 313568abb460107a968e4e2764bde10c34e3bc7a68cc9daca44ea8e523a47584
- Enrichment time
- 2026-06-26T08:51:40Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.