Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign
ID: d0a23e56-33bd-5225-8287-287ccc71ed74
STIX ID: report--d0a23e56-33bd-5225-8287-287ccc71ed74
Feed Name: The Hacker News
A Chinese-speaking APT actor identified as CL-STA-1062 is conducting sustained campaigns against Southeast Asian government entities and critical infrastructure, deploying a bespoke .NET backdoor named TinyRCT (PerfWatson2.exe) alongside ASPX web shells and open-source tooling to perform reconnaissance, lateral movement, command execution, file exfiltration, screenshots, and self-deletion; the report details delivery via a malicious chrome_setup.zip that uses an AppDomainManager DLL to fetch the backdoor, provides C2 IPs and filenames (e.g., 45.32.113.172, 139.180.134.221, PerfWatson2.exe, MyAppDomainManager.dll), and attributes at least 10 breaches between October and December 2025.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
