Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Chinese APT Group Deploys TinyRCT in Southeast Asia

Chinese APT Group Deploys TinyRCT in Southeast Asia

Posted on June 26, 2026 By CWS

A sophisticated Chinese-speaking advanced persistent threat (APT) group has been identified deploying a novel backdoor named TinyRCT in cyber operations targeting government and critical infrastructure sectors in Southeast Asia. The hacking entity, referred to as CL-STA-1062, has been linked to past campaigns impacting state-owned enterprises within the energy and government sectors. These activities parallel those of UAT-7237, a group first noted by Cisco Talos in 2025 for attacking web infrastructure in Taiwan.

Ongoing Cyber Threats in East Asia

According to Palo Alto Networks Unit 42, CL-STA-1062 has been consistently targeting strategic industries across East Asia since March 2022. This suggests a sustained cyber threat presence in the region. The APT relies heavily on a mixed toolkit, employing both commonly available open-source resources like SoftEther VPN, Mimikatz, and VNT, alongside custom-developed tools such as the newly discovered TinyRCT.

The TinyRCT backdoor is engineered to perform various malicious activities, including executing arbitrary commands, file enumeration and exfiltration, screen capture, and self-deletion from compromised systems.

Details of Recent Attacks

In a notable September 2025 campaign, CL-STA-1062 successfully infiltrated a Southeast Asian government entity, using a web shell for data exfiltration from an MS SQL server. The campaign also involved reconnaissance activities on a separate government body within the same nation, indicating a strategy to expand access within the network. Unit 42 reported breaching at least ten organizations in the region between October and December 2025.

Since mid-2025, the group has focused on critical infrastructure, exploiting vulnerabilities and establishing persistence using ASPX web shells. These entry points allowed further deployment of payloads, including SoftEther VPN components and disguised RAR archives with additional tools.

Technical Analysis of TinyRCT

TinyRCT, identified as a previously unknown .NET backdoor, operates through a persistent channel with a remote server, utilizing AES-128 encryption for data exchange. The backdoor includes functionalities such as system reconnaissance, command execution, file transfer, and self-concealment.

The malware communicates with its command-and-control server using a beaconing model, with a default 10-second interval between exchanges. It retrieves instructions via GET requests while transmitting extracted data through POST requests.

The delivery mechanism for TinyRCT involves a malicious archive disguised as “chrome_setup.zip,” containing a legitimate executable and a rogue DLL. This setup triggers an AppDomainManager injection attack to download and execute the backdoor.

Palo Alto Networks Unit 42 emphasizes that the presence of TinyRCT highlights the group’s capability to develop tailored tools to enhance their attack arsenal. Given the targeted nature of their campaigns and their custom malware development, the threat posed by CL-STA-1062 remains significant for Southeast Asia.

The Hacker News Tags:APT group, Backdoor, Chinese APT, CL-STA-1062, cyber espionage, Cybersecurity, Malware, Southeast Asia, TinyRCT, Unit 42

Post navigation

Previous Post: Amazon Q Flaw Exposes Code Execution and Cloud Risks
Next Post: Critical Linux Kernel Exploit Grants Root Access

Related Posts

Pro-Iranian Hacktivist Group Leaks Personal Records from the 2024 Saudi Games Pro-Iranian Hacktivist Group Leaks Personal Records from the 2024 Saudi Games The Hacker News
Trust Wallet Chrome Extension Hack Drains .5M via Shai-Hulud Supply Chain Attack Trust Wallet Chrome Extension Hack Drains $8.5M via Shai-Hulud Supply Chain Attack The Hacker News
Credential Theft and Remote Access Surge as AllaKore, PureRAT, and Hijack Loader Proliferate Credential Theft and Remote Access Surge as AllaKore, PureRAT, and Hijack Loader Proliferate The Hacker News
CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems The Hacker News
Enterprise Credentials at Risk – Same Old, Same Old? Enterprise Credentials at Risk – Same Old, Same Old? The Hacker News
Meta to Train AI on E.U. User Data From May 27 Without Consent; Noyb Threatens Lawsuit Meta to Train AI on E.U. User Data From May 27 Without Consent; Noyb Threatens Lawsuit The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Linux Kernel Exploit Grants Root Access
  • Chinese APT Group Deploys TinyRCT in Southeast Asia
  • Amazon Q Flaw Exposes Code Execution and Cloud Risks
  • Klue Data Breach Expands Amidst Hacker Dispute
  • Guardian Agents: Enhancing Identity Governance for AI

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Linux Kernel Exploit Grants Root Access
  • Chinese APT Group Deploys TinyRCT in Southeast Asia
  • Amazon Q Flaw Exposes Code Execution and Cloud Risks
  • Klue Data Breach Expands Amidst Hacker Dispute
  • Guardian Agents: Enhancing Identity Governance for AI

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark