INTEL_REPORT
Palo Alto Networks Unit 42 · published 6/25/2026, 10:00:52 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure Government entities and critical infrastructure were targeted for espionage in SE Asia by attackers using a hybrid toolkit, including custom TinyRCT backdoor. The post CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure appeared first on Unit 42 . CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure Menu Tools ATOMs Security Consulting About Us Under At…
https://unit42.paloaltonetworks.com/cl-sta-1062-tinyrct-backdoor
sha256:55516d10728714a87ec3c4f89f051cee4e2c42b8ea9afae29312ec913d213eb5
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
| Type | Value | Link |
|---|---|---|
| domain | cmd.exe | Open → |
| domain | vmtools.exe | Open → |
| domain | exe.config | Open → |
| sha256 | f34bd1d485de437fe18360d1e850c3fd64415e49d691e610711d8d232071a0b1 | Open → |
| sha256 | 00e09754526d0fe836ba27e3144ae161b0ecd3774abec5560504a16a67f0087c | Open → |
| sha256 | 4e1f8888d020decd09799ec946f1bf677cac6612b24582ddbf4d8ede425d8384 | Open → |
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| sha256 | 9b481b69cd91b09fa7bae7428f646dd89473a4c03393e43da81fe756cde1c472 | Open → |
| sha256 | cbfe8de6ffadbb1d396f61e63eb18e8b11c29527c1528641e3223d4c516cf7c3 | Open → |
| sha256 | dce5df29bddff5a4ddaea5c4fec14da91f7b69063a6e1c45ed61e5da4fc6c87b | Open → |
| ip | 139.180.134.221 | Open → |
| ip | 45.32.113.172 | Open → |
| ip | 202.182.102.5 | Open → |
| ip | 45.76.210.43 | Open → |
| domain | perfwatson2.exe | Open → |
| domain | choice.exe | Open → |
| domain | myappdomainmanager.dll | Open → |
| domain | 5f0117.zip | Open → |
| domain | 5fbridge.config | Open → |
| domain | win-vpn.rar | Open → |