VMTech
Discuss a project

TinyRCT: Chinese-language APT targets government and energy sectors in Southeast Asia

TinyRCT: Chinese-language APT targets government and energy sectors in Southeast Asia

Colleagues, a cybersecurity alert: Chinese-language APT CL-STA-1062 deploys a new .NET backdoor, TinyRCT, against government entities and critical infrastructure in Southeast Asia.

Key facts:
- Operators use an ASPX web shell, SoftEther, VNT, Mimikatz and TinyRCT.
- TinyRCT (PerfWatson2.exe) executes commands, exfiltrates files, captures screenshots, cleans traces and communicates with C2 over HTTP (AES-128); beacon interval ~10 s.
- Delivered via chrome_setup.zip: a legitimate exe plus a malicious DLL that downloads TinyRCT; one campaign exfiltrated web-server source code.

Why it matters: targeting critical infrastructure and a custom backdoor increase risk of prolonged espionage and data leakage.

What mitigation steps do you consider priorities?

#cybersecurity #APT #infrastructure #malware

Open analytics
On the site 1 views
min read 1 28.06.2026
On Instagram 4 views
On Instagram 1 reach
Instagram

TinyRCT: Chinese-language APT targets government and energy sectors in Southeast Asia

Open the post on Instagram ↗