Skip to content
Chinese APT CL-STA-1062 Deploys TinyRCT Backdoor Against Southeast Asian Targets

Chinese APT CL-STA-1062 Deploys TinyRCT Backdoor Against Southeast Asian Targets

First seen 26 Jun 2026, 13:53 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •June 27, 2026 at 11:26 UTC
  • •CL-STA-1062 has targeted Southeast Asian government and energy sectors with TinyRCT backdoor.
  • •The malware employs advanced evasion techniques, including strict execution checks and trusted process injection.
  • •Persistent operations since March 2022 indicate a long-term focus on regional critical infrastructure.

The Chinese-speaking threat group CL-STA-1062 has been actively deploying a new .NET backdoor named TinyRCT against government and critical energy infrastructure in Southeast Asia throughout 2025. This campaign utilizes a combination of open-source tools and custom malware, including SoftEther VPN for tunneling and Mimikatz for credential harvesting. The TinyRCT backdoor, disguised as PerfWatson2.exe, employs strict execution checks to evade detection and establishes a persistent, encrypted communication channel with its command-and-control server. The group has been linked to ongoing operations since March 2022 and has targeted state-owned enterprises, leading to significant data exfiltration. Observed activities include database breaches and prolonged access to critical energy organizations. The malware's stealthy infection chain involves a socially engineered dropper that leverages trusted processes for execution.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 105d ago How this analysis works

Timeline

2022-03-01
CL-STA-1062 activity began
The threat group has been active since at least March 2022, targeting various sectors.
Gbhackers
2025-01-01
TinyRCT backdoor deployed
The TinyRCT backdoor was observed in campaigns against Southeast Asian government and energy sectors.
Gbhackers
2025-06-01
Data exfiltration incidents reported
Significant data breaches from state-owned enterprises were reported, indicating the scale of the attacks.
Gbhackers
2026-06-26
Unit 42 report published
Palo Alto Networks Unit 42 released a report detailing the activities and tools used by CL-STA-1062.
Securityaffairs.Co

More articles in this cluster (7)

Following this threat?

Track Cl-sta and TinyRCT in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed