TinyRCT: Chinese-language APT targets government and energy sectors in Southeast Asia

Colleagues, a cybersecurity alert: Chinese-language APT CL-STA-1062 deploys a new .NET backdoor, TinyRCT, against government entities and critical infrastructure in Southeast Asia.
Key facts:
- Operators use an ASPX web shell, SoftEther, VNT, Mimikatz and TinyRCT.
- TinyRCT (PerfWatson2.exe) executes commands, exfiltrates files, captures screenshots, cleans traces and communicates with C2 over HTTP (AES-128); beacon interval ~10 s.
- Delivered via chrome_setup.zip: a legitimate exe plus a malicious DLL that downloads TinyRCT; one campaign exfiltrated web-server source code.
Why it matters: targeting critical infrastructure and a custom backdoor increase risk of prolonged espionage and data leakage.
What mitigation steps do you consider priorities?
#cybersecurity #APT #infrastructure #malware

