Chinese-Speaking Hackers Deploy TinyRCT Backdoor Against Critical Energy Infrastructure
ID: 4a473867-5d3a-5df1-be5e-8ef12ceb9bdd
STIX ID: report--4a473867-5d3a-5df1-be5e-8ef12ceb9bdd
Feed Name: GBHackers
CL-STA-1062, a Chinese-speaking threat cluster, deployed a newly discovered .NET backdoor named TinyRCT in 2025 campaigns targeting government and critical energy organizations in Southeast Asia. The campaign pairs publicly available tooling (SoftEther VPN, VNT, yuze, Mimikatz) and ASPX web shells with a stealthy C# RAT distributed via a signed chrome_setup.exe dropper and a MyAppDomainManager.dll loader that enforces execution-path checks and establishes AES-128-CBC HTTP C2 for beacons, file exfiltration, and remote commands; analysts observed database and web-server code exfiltration and long-term access to state-owned energy entities. The report includes hashes and C2/staging IPs, links the actor to prior activity since 2022, and provides detection and mitigation guidance (web-app defenses, allowlisting, behavioral monitoring, and incident response actions).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
