logo

Chinese APT CL-STA-1062 Deploys TinyRCT Backdoor Against Southeast Asian Targets

ID: 45958d43-4f37-589d-bcc2-38a477c168ca

STIX ID: report--45958d43-4f37-589d-bcc2-38a477c168ca

Feed Name: ThreatCluster

Threat Score
88/100

Date Published: 2026-06-26

Date Updated: 2026-06-27

...
...

CL-STA-1062, a Chinese-speaking threat actor, has been running a 2025 campaign against Southeast Asian government and energy sectors using a disguised .NET backdoor called TinyRCT; the campaign leverages socially engineered droppers, trusted-process injection, SoftEther VPN, and Mimikatz to maintain persistent, encrypted C2 and exfiltrate data, with activity traced back to March 2022.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.