Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign
A Chinese-speaking APT actor has been linked to a new custom backdoor called TinyRCT, targeting government entities and critical infrastructure in Southeast Asia. The threat actor, known as CL-STA-1062, has been attributed to previous campaigns in East Asia since March 2022.
Intelligence analysis by Llama 3.3 70B

The Chinese-speaking APT actor CL-STA-1062 has introduced a new custom backdoor called TinyRCT, which enables system reconnaissance, command execution, and file uploads, among other capabilities. The backdoor is part of a broader campaign targeting critical infrastructure in Southeast Asia.
A group of hackers has created a new tool to help them break into computers and steal information. This tool is called TinyRCT and it's very good at hiding itself and sending information back to the hackers. The hackers are using this tool to target important computers in Southeast Asia, and it's a big concern for security experts.
Analysis
Introduction to TinyRCT
The TinyRCT backdoor is a previously undocumented, bespoke malware that has been linked to the Chinese-speaking APT actor CL-STA-1062. According to Palo Alto Networks Unit 42, TinyRCT is equipped to run arbitrary commands, enumerate files and exfiltrate them, capture the device's screen, and delete itself from the compromised host. The backdoor operates on a beaconing model, with a default 10-second sleep interval between requests, and establishes a persistent communication channel with a remote server over HTTP, using AES-128 encryption in CBC mode.
Technical Capabilities of TinyRCT
The technical capabilities of TinyRCT are significant, and include the ability to execute commands, upload and download files, and capture screenshots. The backdoor also has the ability to delete itself from the compromised host, making it difficult to detect and remove. The use of AES-128 encryption in CBC mode adds an additional layer of complexity to the backdoor's communication protocol, making it harder to intercept and analyze.
Implications of the TinyRCT Discovery
The discovery of TinyRCT has significant implications for the security of critical infrastructure in Southeast Asia. The use of custom malware by CL-STA-1062 suggests a high level of sophistication and adaptability, and highlights the need for increased vigilance and security measures to prevent such attacks. The fact that TinyRCT has been linked to previous campaigns in East Asia since March 2022 suggests that CL-STA-1062 is a persistent and ongoing threat, and that the region remains a key target for the threat actor.
Key points
- Chinese-speaking APT actor CL-STA-1062 has introduced a new custom backdoor called TinyRCT
- TinyRCT enables system reconnaissance, command execution, and file uploads, among other capabilities
- The backdoor is part of a broader campaign targeting critical infrastructure in Southeast Asia
The discovery of TinyRCT may lead to increased awareness and vigilance among security experts and organizations in Southeast Asia, potentially preventing future attacks. Additionally, the identification of the backdoor's technical capabilities may enable the development of more effective detection and removal tools, reducing the risk of compromise.
The discovery of TinyRCT highlights the ongoing threat posed by CL-STA-1062 to critical infrastructure in Southeast Asia, and suggests that the region remains a key target for the threat actor. The use of custom malware and open-source tools by the threat actor may make it difficult to detect and prevent future attacks, potentially leading to significant financial and reputational losses for affected organizations.


