# Chinese-Speaking APT Deploys New TinyRCT Backdoor in Coordinated Southeast Asia Campaign
A Chinese-speaking advanced persistent threat (APT) actor designated CL-STA-1062 has been conducting a sustained cyber espionage campaign against government entities and critical infrastructure across Southeast Asia, deploying a previously undocumented custom backdoor called TinyRCT as part of a broader toolkit aimed at establishing persistent remote access.
According to a technical report from Palo Alto Networks Unit 42, the threat group has been actively targeting state-owned enterprises in the energy and government sectors since at least March 2022, with recent campaigns detected between October and December 2025 compromising at least 10 different organizations. The discovery of TinyRCT marks an escalation in the group's technical capabilities, signaling a shift from reliance on open-source utilities to developing proprietary malware tailored to their operational objectives.
## The Threat
CL-STA-1062 represents a sustained and evolving threat to Southeast Asian infrastructure. The group has demonstrated:
Unit 42 noted that CL-STA-1062 shares technical overlaps with UAT-7237, a hacking group previously flagged by Cisco Talos in August 2025 for operations targeting web infrastructure in Taiwan. This linkage suggests potential shared operational infrastructure or personnel, though attribution remains challenging.
## Background and Context
The emergence of TinyRCT comes during an extended period of heightened cyber espionage activity targeting Asia-Pacific infrastructure. The threat actor's focus on Southeast Asia reflects the region's growing strategic importance and the proliferation of critical infrastructure dependent on aging or inadequately secured systems.
### Campaign Timeline
### Attack Chain Overview
The typical attack sequence observed by Unit 42 follows this pattern:
1. Initial Access: Exploitation of vulnerabilities in internet-facing systems, followed by ASPX web shell deployment
2. Reconnaissance: Network scanning and system enumeration via web shells
3. Lateral Movement: Identification of adjacent systems and opportunities for privilege escalation
4. Persistence: Deployment of SoftEther VPN components and remote access tools
5. Data Exfiltration: Command execution and large-scale file theft
In one documented case, attackers successfully exfiltrated an entire directory of web server source code from a government entity while simultaneously conducting reconnaissance against a separate organization in the same nation.
## Technical Details
### TinyRCT Backdoor Specifications
TinyRCT is a lightweight .NET-based remote access trojan engineered for stealth and functionality. Key technical characteristics include:
| Feature | Capability |
|---------|-----------|
| Payload Name | PerfWatson2.exe |
| Encryption | AES-128 (CBC mode) |
| Communication | HTTP GET/POST requests |
| Beaconing Interval | 10 seconds (default) |
| C2 Infrastructure | 45.32.113[.]172 |
| Persistence Mechanism | Registry modification |
| Evasion Techniques | Sandboxed environment detection |
Functional Capabilities:
### Delivery Mechanism
The malware employs a multi-stage delivery approach disguised as legitimate software:
1. Stage 1: Malicious archive named "chrome_setup.zip" containing three components:
- Legitimate Chrome installer executable ("chrome_setup.exe")
- Configuration file ("chrome_setup.exe.config")
- Rogue managed DLL ("MyAppDomainManager.dll")
2. Stage 2: AppDomainManager injection attack is triggered, loading the malicious DLL
3. Stage 3: DLL contacts remote server (139.180.134[.]221) to retrieve the actual backdoor ("PerfWatson2.exe")
4. Stage 4: TinyRCT establishes persistent communication with C2 infrastructure
### Operational Toolset
Beyond TinyRCT, CL-STA-1062 leverages a hybrid approach combining open-source and custom tools:
## Implications for Organizations
### Exposure and Risk
Organizations operating critical infrastructure in Southeast Asia face direct and immediate risk. The threat actor's demonstrated ability to:
...suggests a capability to support intelligence gathering, espionage, and potentially operational disruption objectives.
### Data at Risk
Confirmed exfiltration includes:
This data could facilitate secondary attacks, vulnerability discovery, or provide adversaries with intelligence on government and critical infrastructure operations.
## Recommendations
### Immediate Actions
Detection and Response:
Containment:
### Medium-Term Hardening
### Long-Term Security Strategy
---
## HackWire Analysis
This campaign represents a concerning evolution in cyber espionage targeting Southeast Asia. What distinguishes CL-STA-1062 is not singular technical innovation—the use of AppDomainManager injection and AES-128 beaconing are well-established techniques—but rather the organized, methodical approach to infrastructure compromise at scale.
The fact that Unit 42 detected activity across at least 10 organizations in just a three-month window suggests either a significant operational scaling or improved visibility into previously undetected activity. More troubling is the pattern of reconnaissance-before-exploitation: the group scans for vulnerabilities, establishes web shell footholds, then stages secondary payloads *only after* confirming network access and identifying high-value targets. This is adversary tradecraft, not indiscriminate worm-like behavior.
The timing also matters. Targeting government energy sector entities in Southeast Asia, combined with the group's documented focus on Taiwan infrastructure, points to state-level intelligence gathering aimed at regional power dynamics, supply chain vulnerabilities, or infrastructure weaknesses that could inform future military or economic leverage. When a Chinese-speaking APT spends over four years methodically mapping government and energy infrastructure across Southeast Asia, that's not opportunistic cybercrime—that's infrastructure intelligence preparation.
For defenders, the tactical insight is this: You will not detect TinyRCT or AppDomainManager injection through signature-based antivirus. Detection requires either (1) network-based monitoring for the distinctive beaconing pattern (10-second HTTP polls to a new C2), (2) behavioral EDR that flags DLL injection attacks, or (3) web shell hunting using ASPX file discovery and upload log analysis. Organizations waiting for a vendor signature update will already be compromised.
— *HackWire Editorial*
---
## Related Coverage