ThreatCluster

Chinese Threat Group CL-STA-1062 Deploys TinyRCT Backdoor in Southeast Asia

First seen 26 Jun 2026, 13:53 UTC GbhackersCybersecuritynews 83% similarity 73
Share:

Article Content

Browse articles
ThreatCluster

The Chinese-speaking threat cluster CL-STA-1062 has been actively deploying a .NET backdoor named TinyRCT against government and critical energy infrastructure in Southeast Asia throughout 2025. The group has targeted state-owned enterprises, utilizing a combination of open-source tools and custom malware. Key tools include SoftEther VPN for tunneling and VNT and yuze for command-and-control operations. The campaign has been ongoing since at least March 2022, indicating a long-term strategy against critical sectors. The impact is significant, with multiple government agencies and energy sectors affected. The use of bespoke malware alongside publicly available utilities highlights the group's sophisticated approach. Current status indicates continued activity with no immediate resolution in sight.

Key Points: • CL-STA-1062 has deployed the TinyRCT backdoor against Southeast Asian government entities. • The threat group combines open-source tools with custom malware for its operations. • The campaign has been active since at least March 2022, targeting critical infrastructure.

ThreatCluster AI

Timeline

2022-03-01
CL-STA-1062 begins operations
The Chinese-speaking threat group starts targeting government agencies and critical infrastructure in Southeast Asia.
Cybersecuritynews
2025-01-01
TinyRCT backdoor identified
Security researchers discover the TinyRCT backdoor being used in targeted campaigns against critical sectors.
Gbhackers
2025-06-01
Campaign intensifies
CL-STA-1062 escalates its attacks, focusing on state-owned enterprises across Southeast Asia.
Cybersecuritynews
2026-06-26
Current status of campaign
The threat group continues its operations with no signs of cessation, impacting multiple sectors.
Gbhackers

Community

Browse all →