Chinese APT CL-STA-1062 Deploys TinyRCT Backdoor Against Southeast Asian Targets
ID: 45958d43-4f37-589d-bcc2-38a477c168ca
STIX ID: report--45958d43-4f37-589d-bcc2-38a477c168ca
Feed Name: ThreatCluster
Threat Score
CL-STA-1062, a Chinese-speaking threat actor, has been running a 2025 campaign against Southeast Asian government and energy sectors using a disguised .NET backdoor called TinyRCT; the campaign leverages socially engineered droppers, trusted-process injection, SoftEther VPN, and Mimikatz to maintain persistent, encrypted C2 and exfiltrate data, with activity traced back to March 2022.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
