{"id":1469,"date":"2026-06-26T17:50:24","date_gmt":"2026-06-26T17:50:24","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1469"},"modified":"2026-06-26T17:50:24","modified_gmt":"2026-06-26T17:50:24","slug":"chinese-speaking-apt-deploys-new-tinyrct-backdoor-in-southeast-asia-campaign","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1469","title":{"rendered":"Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jun 26, 2026<\/span><\/span><span class=\"p-tags\">Cyber Espionage \/ Malware<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgHsYcZgd4WIkN0k-b4_j7JxBgi0R0dzj0jSwSWVgItyIy88VoZK5z8BAiwjmYnou7YLrNuckCgQvnHXV2KYHoNS8WRZbjU1MP5HqvLKkIakvRVuJio7oZeUbi1XsgQVmJ-cDKKWeOzgGouUAzUtJrFRu8CtPQJG-eXCy7aSOx_fyCvGK2tRl12tBbPG7YC\/s1700-e365\/tinyrct.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>A Chinese-speaking advanced persistent threat (APT) actor has been linked to a new custom backdoor called TinyRCT as part of cyber attacks aimed at government entities and critical infrastructure in Southeast Asia.<\/p>\n<p>The activity, particularly aimed at state-owned enterprises in the energy and government sectors, has been attributed to a threat actor called <b>CL-STA-1062<\/b>, which Palo Alto Networks Unit 42 said shares overlaps with UAT-7237, a hacking group that was first flagged by Cisco Talos in August 2025 in relation to a campaign directed against web infrastructure entities in Taiwan.<\/p>\n<p>Unit 42 said it also observed CL-STA-1062 campaigns in prior operations targeting strategic sectors in East Asia since March 2022, suggesting a broader but sustained focus in the region.<\/p>\n<p>\u00abFrom a technical standpoint, the attackers behind CL-STA-1062 rely on a hybrid toolkit,\u00bb Unit 42 <a href=\"https:\/\/unit42.paloaltonetworks.com\/cl-sta-1062-tinyrct-backdoor\/\">said<\/a> in a technical report. \u00abWhile they frequently use common open-source tools such as SoftEther VPN, Mimikatz, and VNT, they have recently introduced TinyRCT, a bespoke, previously undocumented backdoor.\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-cant-stop-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjPEV6-530TOlxG6PjrmdlY623wpBwduZ7t1HV6flcmO5R4q4AmfixDUzW0CrhlvMVNWbhvOIso-UDNTka4W_W9Chrdj_dglwBZwi7DuePM2IMIl-hfUYVIqBXgfpr_2619K8Gptb4LzwJ6gUbi7lWl2M8AFQJsHEaw63Q7tZ6708YGruiHrr0Y2W9YYxLQ\/s728-e100\/ThreatLocker-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>TinyRCT is equipped to run arbitrary commands, enumerate files and exfiltrate them, capture the device&#8217;s screen, and delete itself from the compromised host.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>In one campaign detected in September 2025, the threat actor is said to have infiltrated a Southeast Asian government entity and deployed a web shell to exfiltrate data from an MS SQL server. During the same attack, the threat actors have been found to conduct network reconnaissance on a separate government entity in the same country.<\/p>\n<p>\u00abThis suggests an effort to identify lateral movement opportunities and broaden their access. In one case, we observed the attacker staging and exfiltrating an entire directory of web server source code from the government entity,\u00bb Unit 42 said, adding it detected the breach of at least 10 different organizations in Southeast Asia between October and December 2025.<\/p>\n<p>Since at least mid-2025, CL-STA-1062 has trained its sights on the critical infrastructure, with the adversary scanning multiple entities in the region for vulnerabilities and then establishing a foothold via ASPX web shells that facilitate initial reconnaissance and outbound requests from the infected networks to attacker-controlled infrastructure, leading to the deployment of additional payloads.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjV3f1bO_6uS32u_DSdWw5EMRHwiz8l29LcHlMoIUvCtvm9q_vDVVgx573UAlingeaYu4DuvYrR-At882VtrKD6-j2ee9EOnCHrix632mLOK4nF1_qzmuxKgAQpcFJ3ISaT08Xo-63KbQjeY13YSLuErz7YjMXJewj4JbLsEwgmCmlS7GMt2FdGSf445T4j\/s1700-e365\/code.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjV3f1bO_6uS32u_DSdWw5EMRHwiz8l29LcHlMoIUvCtvm9q_vDVVgx573UAlingeaYu4DuvYrR-At882VtrKD6-j2ee9EOnCHrix632mLOK4nF1_qzmuxKgAQpcFJ3ISaT08Xo-63KbQjeY13YSLuErz7YjMXJewj4JbLsEwgmCmlS7GMt2FdGSf445T4j\/s1700-e365\/code.jpg\" alt=\"\" border=\"0\" data-original-height=\"384\" data-original-width=\"737\"\/><\/a><\/div>\n<p>This includes SoftEther VPN components and RAR archives containing the group&#8217;s toolset, including open-source utilities such as <a href=\"https:\/\/github.com\/P001water\/yuze\">Yuze<\/a> (a SOCKS5 proxy) and <a href=\"https:\/\/github.com\/vnt-dev\/vnt\">VNT<\/a> (a VPN), often disguising them as VMware executables or an XDR agent (e.g., \u00abXDRAgent.exe,\u00bb \u00abvmtools.exe,\u00bb and \u00abvmwared.exe\u00bb).<\/p>\n<p>Further analysis of the campaign&#8217;s infrastructure has led to the discovery of a previously undocumented .NET backdoor dubbed TinyRCT (\u00abPerfWatson2.exe\u00bb), a lightweight remote access trojan that enables system reconnaissance, command execution, file uploads, screenshot capture, remote control, and wipe traces of itself, while taking steps to avoid running in sandboxed environments.<\/p>\n<p>It establishes a persistent communication channel with a remote server (\u00ab45.32.113[.]172\u00bb) over HTTP, but encrypts the exchanged data using AES-128 encryption in CBC mode.<\/p>\n<p>\u00abThe malware operates on a beaconing model, with a default 10-second sleep interval between requests,\u00bb Unit 42 explained. \u00abIt polls the C2 server for instructions using GET requests, while it sends exfiltrated data via POST requests.\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/vpn-threat-report-m\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhFlTC7RrRZGiFAgASS0noWSL0qsQGFVp8-Hvuw9yp3X3VKRuTcb5SsPX09wJzrdIM6pu1_5lS4EeZp7Sx4iYBpNJkrGnpr08yyaS1HQ5_5TxaCsP6O0OtHNuOkesn6CbNjao1GPulCJk-uljYMSfMZfBYNrngpe669t7jlRn1FqiEnXhsFD1WVkpaYIVgh\/s728-e100\/ai-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>As for how TinyRCT is delivered, it takes the form of a malicious archive named \u00abchrome_setup.zip\u00bb containing a legitimate executable (\u00abchrome_setup.exe\u00bb), a configuration file (\u00abchrome_setup.exe.config\u00bb), and a rogue DLL (\u00abMyAppDomainManager.dll\u00bb) that&#8217;s used to trigger an <a href=\"https:\/\/attack.mitre.org\/techniques\/T1574\/014\/\">AppDomainManager injection<\/a> attack to load the malicious DLL, which functions as a downloader by contacting \u00ab139.180.134[.]221\u00bb to retrieve \u00abPerfWatson2.exe.\u00bb<\/p>\n<p>\u00abThe combination of tools observed in this activity cluster reflects a pragmatic approach to tool selection and attack capabilities,\u00bb Unit 42 concluded. \u00abThe attackers behind this cluster continue to leverage common open-source tools such as SoftEther VPN and VNT to facilitate lateral movement.\u00bb<\/p>\n<p>\u00abOur discovery of the TinyRCT backdoor in the attackers&#8217; infrastructure underscores their ability to customize tools to gain specific capabilities. The combination of targeting critical infrastructure and the development of custom malware suggests that CL-STA-1062 activity will continue to pose a threat to the region.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Jun 26, 2026Cyber Espionage \/ Malware A Chinese-speaking advanced persistent threat (APT) actor has been linked to a new custom backdoor called TinyRCT as part of cyber attacks aimed&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1470,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[1528,594,179,6,2216,297,593,2217],"class_list":["post-1469","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-apt","tag-asia","tag-backdoor","tag-campaign","tag-chinesespeaking","tag-deploys","tag-southeast","tag-tinyrct"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1469","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1469"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1469\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1470"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1469"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1469"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1469"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}