Chinese APT CL-STA-1062 Expands Attacks on Southeast Asian Critical Infrastructure With Custom Malware
2026-06-27T02:51:42Z•ec8f3e3375bd222980b9c58c7c392df52db03db09a6c79cb176814bebbc59d67
CISACL-STA-1062CVE-2026-12569CVE-2026-20245FlexPLMKnown-Exploited-VulnerabilitiesPTC-WindchillTinyRCTaptbackdoorchina-linkedciscocritical-infrastructurecrypto-theftcurldata-breachmacOS.Gaslight (Gaslight)macospolymarketsd-wansoutheast-asiasupply-chaintata-electronicsthird-party-breachvulnerabilities
What happened
Multiple high-impact security developments: Palo Alto Unit 42 links Chinese-speaking APT CL-STA-1062 to persistent operations in East and Southeast Asia using custom tooling and a new TinyRCT backdoor targeting government and energy networks. Google/Mandiant reported active exploitation of Cisco Catalyst SD‑WAN zero-day CVE-2026-20245 months before disclosure, while CISA added Cisco and PTC Windchill/FlexPLM flaws (including CVE-2026-12569) to its Known Exploited Vulnerabilities catalog. Other notable incidents include a Polymarket third‑party supply-chain compromise that enabled ~$2.94M in盗/失
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- ec8f3e3375bd222980b9c58c7c392df52db03db09a6c79cb176814bebbc59d67
- Enrichment time
- 2026-06-27T02:51:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.