# Chinese-Speaking APT Deploys New TinyRCT Backdoor in Coordinated Southeast Asia Campaign


A Chinese-speaking advanced persistent threat (APT) actor designated CL-STA-1062 has been conducting a sustained cyber espionage campaign against government entities and critical infrastructure across Southeast Asia, deploying a previously undocumented custom backdoor called TinyRCT as part of a broader toolkit aimed at establishing persistent remote access.


According to a technical report from Palo Alto Networks Unit 42, the threat group has been actively targeting state-owned enterprises in the energy and government sectors since at least March 2022, with recent campaigns detected between October and December 2025 compromising at least 10 different organizations. The discovery of TinyRCT marks an escalation in the group's technical capabilities, signaling a shift from reliance on open-source utilities to developing proprietary malware tailored to their operational objectives.


## The Threat


CL-STA-1062 represents a sustained and evolving threat to Southeast Asian infrastructure. The group has demonstrated:


  • Broad targeting: Government entities, critical infrastructure operators, and state-owned enterprises
  • Operational persistence: Continuous activity spanning over four years with regular campaign cycles
  • Technical sophistication: Custom malware development paired with living-off-the-land tactics
  • Lateral movement capability: Evidence of network reconnaissance across multiple target organizations

  • Unit 42 noted that CL-STA-1062 shares technical overlaps with UAT-7237, a hacking group previously flagged by Cisco Talos in August 2025 for operations targeting web infrastructure in Taiwan. This linkage suggests potential shared operational infrastructure or personnel, though attribution remains challenging.


    ## Background and Context


    The emergence of TinyRCT comes during an extended period of heightened cyber espionage activity targeting Asia-Pacific infrastructure. The threat actor's focus on Southeast Asia reflects the region's growing strategic importance and the proliferation of critical infrastructure dependent on aging or inadequately secured systems.


    ### Campaign Timeline


  • March 2022 onwards: Initial operations targeting East Asian strategic sectors
  • August 2025: UAT-7237 attributed to Taiwan web infrastructure campaign (Cisco Talos)
  • September 2025: TinyRCT deployed against Southeast Asian government entity; lateral movement observed
  • October–December 2025: Peak operational activity; 10+ organizations compromised

  • ### Attack Chain Overview


    The typical attack sequence observed by Unit 42 follows this pattern:


    1. Initial Access: Exploitation of vulnerabilities in internet-facing systems, followed by ASPX web shell deployment

    2. Reconnaissance: Network scanning and system enumeration via web shells

    3. Lateral Movement: Identification of adjacent systems and opportunities for privilege escalation

    4. Persistence: Deployment of SoftEther VPN components and remote access tools

    5. Data Exfiltration: Command execution and large-scale file theft


    In one documented case, attackers successfully exfiltrated an entire directory of web server source code from a government entity while simultaneously conducting reconnaissance against a separate organization in the same nation.


    ## Technical Details


    ### TinyRCT Backdoor Specifications


    TinyRCT is a lightweight .NET-based remote access trojan engineered for stealth and functionality. Key technical characteristics include:


    | Feature | Capability |

    |---------|-----------|

    | Payload Name | PerfWatson2.exe |

    | Encryption | AES-128 (CBC mode) |

    | Communication | HTTP GET/POST requests |

    | Beaconing Interval | 10 seconds (default) |

    | C2 Infrastructure | 45.32.113[.]172 |

    | Persistence Mechanism | Registry modification |

    | Evasion Techniques | Sandboxed environment detection |


    Functional Capabilities:

  • Remote command execution with arbitrary code execution
  • File enumeration and exfiltration via POST requests
  • Screenshot capture for surveillance
  • System reconnaissance and environment profiling
  • Self-deletion and trace wiping
  • AppDomainManager injection attack for DLL loading

  • ### Delivery Mechanism


    The malware employs a multi-stage delivery approach disguised as legitimate software:


    1. Stage 1: Malicious archive named "chrome_setup.zip" containing three components:

    - Legitimate Chrome installer executable ("chrome_setup.exe")

    - Configuration file ("chrome_setup.exe.config")

    - Rogue managed DLL ("MyAppDomainManager.dll")


    2. Stage 2: AppDomainManager injection attack is triggered, loading the malicious DLL

    3. Stage 3: DLL contacts remote server (139.180.134[.]221) to retrieve the actual backdoor ("PerfWatson2.exe")

    4. Stage 4: TinyRCT establishes persistent communication with C2 infrastructure


    ### Operational Toolset


    Beyond TinyRCT, CL-STA-1062 leverages a hybrid approach combining open-source and custom tools:


  • SoftEther VPN: Tunnel creation and encrypted communications
  • Mimikatz: Credential harvesting and privilege escalation
  • VNT & Yuze: VPN and SOCKS5 proxy components
  • ASPX Web Shells: Initial reconnaissance and network enumeration
  • Legitimate Software Masquerading: Attackers disguise tools as "XDRAgent.exe," "vmtools.exe," and "vmwared.exe" to avoid detection

  • ## Implications for Organizations


    ### Exposure and Risk


    Organizations operating critical infrastructure in Southeast Asia face direct and immediate risk. The threat actor's demonstrated ability to:


  • Identify and exploit publicly-facing vulnerabilities
  • Deploy persistent backdoors within network environments
  • Conduct lateral movement across administrative boundaries
  • Exfiltrate sensitive source code and operational data

  • ...suggests a capability to support intelligence gathering, espionage, and potentially operational disruption objectives.


    ### Data at Risk


    Confirmed exfiltration includes:

  • Web server source code (complete directory structures)
  • SQL database contents (MS SQL servers targeted)
  • System configuration information
  • Network topology and architecture details

  • This data could facilitate secondary attacks, vulnerability discovery, or provide adversaries with intelligence on government and critical infrastructure operations.


    ## Recommendations


    ### Immediate Actions


    Detection and Response:


  • Scan internet-facing systems for ASPX web shells using web server logs and file integrity monitoring
  • Monitor for HTTP beaconing patterns to command server 45.32.113[.]172 and 139.180.134[.]221
  • Analyze network traffic for AES-128 encrypted communication over HTTP to unknown destinations
  • Review web server logs for suspicious POST/GET requests and unusual command execution patterns

  • Containment:


  • Isolate affected systems from network immediately upon detection
  • Revoke all credentials from compromised accounts and systems
  • Block identified C2 IP addresses at perimeter firewalls and proxy servers
  • Preserve forensic evidence for incident analysis

  • ### Medium-Term Hardening


  • Implement web application firewalls (WAF) with rules to detect and block ASPX web shell uploads
  • Deploy endpoint detection and response (EDR) solutions with behavioral analysis capability
  • Enforce multi-factor authentication (MFA) across all remote access systems
  • Conduct vulnerability assessments on all internet-facing infrastructure
  • Implement strict code signing policies to prevent unsigned DLL execution
  • Enable AppDomainManager injection prevention where supported

  • ### Long-Term Security Strategy


  • Establish 24/7 security monitoring and incident response capabilities
  • Implement network segmentation to limit lateral movement
  • Conduct regular security awareness training emphasizing social engineering risks
  • Maintain detailed asset inventories and baseline configurations
  • Develop incident response playbooks specific to APT campaigns
  • Participate in threat intelligence sharing communities to accelerate detection and response

  • ---


    ## HackWire Analysis


    This campaign represents a concerning evolution in cyber espionage targeting Southeast Asia. What distinguishes CL-STA-1062 is not singular technical innovation—the use of AppDomainManager injection and AES-128 beaconing are well-established techniques—but rather the organized, methodical approach to infrastructure compromise at scale.


    The fact that Unit 42 detected activity across at least 10 organizations in just a three-month window suggests either a significant operational scaling or improved visibility into previously undetected activity. More troubling is the pattern of reconnaissance-before-exploitation: the group scans for vulnerabilities, establishes web shell footholds, then stages secondary payloads *only after* confirming network access and identifying high-value targets. This is adversary tradecraft, not indiscriminate worm-like behavior.


    The timing also matters. Targeting government energy sector entities in Southeast Asia, combined with the group's documented focus on Taiwan infrastructure, points to state-level intelligence gathering aimed at regional power dynamics, supply chain vulnerabilities, or infrastructure weaknesses that could inform future military or economic leverage. When a Chinese-speaking APT spends over four years methodically mapping government and energy infrastructure across Southeast Asia, that's not opportunistic cybercrime—that's infrastructure intelligence preparation.


    For defenders, the tactical insight is this: You will not detect TinyRCT or AppDomainManager injection through signature-based antivirus. Detection requires either (1) network-based monitoring for the distinctive beaconing pattern (10-second HTTP polls to a new C2), (2) behavioral EDR that flags DLL injection attacks, or (3) web shell hunting using ASPX file discovery and upload log analysis. Organizations waiting for a vendor signature update will already be compromised.


    — *HackWire Editorial*


    ---


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)