Gbhackers Chinese APT CL-STA-1062 Deploys TinyRCT Backdoor Against Southeast Asian Targets
Article Content
- •CL-STA-1062 has targeted Southeast Asian government and energy sectors with TinyRCT backdoor.
- •The malware employs advanced evasion techniques, including strict execution checks and trusted process injection.
- •Persistent operations since March 2022 indicate a long-term focus on regional critical infrastructure.
The Chinese-speaking threat group CL-STA-1062 has been actively deploying a new .NET backdoor named TinyRCT against government and critical energy infrastructure in Southeast Asia throughout 2025. This campaign utilizes a combination of open-source tools and custom malware, including SoftEther VPN for tunneling and Mimikatz for credential harvesting. The TinyRCT backdoor, disguised as PerfWatson2.exe, employs strict execution checks to evade detection and establishes a persistent, encrypted communication channel with its command-and-control server. The group has been linked to ongoing operations since March 2022 and has targeted state-owned enterprises, leading to significant data exfiltration. Observed activities include database breaches and prolonged access to critical energy organizations. The malware's stealthy infection chain involves a socially engineered dropper that leverages trusted processes for execution.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (7)
Following this threat?
Track Cl-sta and TinyRCT in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…