AUTO-UPDATED

Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign

A Chinese-speaking threat actor known as CL-STA-1062 is targeting government and energy sectors in Southeast Asia using a custom backdoor called TinyRCT to exfiltrate sensitive data.

Key Points

  • Palo Alto Networks Unit 42 identified CL-STA-1062, a group linked to at least 10 organizational breaches between October and December 2025.
  • The group utilizes TinyRCT, a previously undocumented .NET backdoor capable of remote command execution, file exfiltration, and screen capture.
  • Attackers gain initial access by deploying ASPX web shells and using AppDomainManager injection techniques disguised as legitimate software like Google Chrome.
  • The threat actor employs a hybrid toolkit, combining custom malware with open-source utilities such as SoftEther VPN, Mimikatz, and the Yuze SOCKS5 proxy.
  • Operations involve scanning critical infrastructure for vulnerabilities to facilitate lateral movement and long-term persistence within compromised government networks.

Why it Matters

This campaign highlights a sophisticated, sustained effort by state-aligned actors to infiltrate critical infrastructure and government entities across Southeast Asia. The use of custom, lightweight backdoors like TinyRCT alongside common tools demonstrates an evolving strategy that complicates detection and increases the risk of long-term data espionage.
Internet Published by info@thehackernews.com (The Hacker News)
Read original