TinyRCT is a previously undocumented lightweight C#/.NET backdoor and remote access trojan used by the China-linked threat cluster CL-STA-1062, which overlaps with activity tracked as UAT-7237. It has been deployed in cyber-espionage operations targeting government entities and critical infrastructure in Southeast Asia, particularly state-owned organizations in the energy and government sectors. The malware is designed to provide persistent remote access while maintaining a small footprint and evading analysis.
TinyRCT supports arbitrary command execution through the Windows command interpreter, remote host management, directory and file enumeration, file reading, staged file download, screenshot capture, and encrypted file exfiltration. Exfiltrated data is chunked and compressed before transmission, and command-and-control traffic is protected with AES-128-CBC over HTTP. Reported anti-analysis and stealth features include execution-environment checks, masquerading as legitimate software components, and a self-destruct routine that removes the implant and associated persistence artifacts to hinder forensic investigation.
Observed delivery involved a DLL side-loading and AppDomainManager injection chain packaged to resemble legitimate software installation, after which the loader retrieved the TinyRCT payload and established persistence via a scheduled task. TinyRCT has been used alongside a broader intrusion toolkit that included web shells for initial compromise, credential theft utilities, tunneling tools, and privilege-escalation tooling. Its role in these operations was to maintain access, execute operator commands, support reconnaissance and post-compromise activity, and facilitate intelligence collection from compromised Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Additionally, the threat group used TinyRCT for the first time, a previously undocumented backdoor designed to provide persistent access and control over compromised systems.
Additionally, the threat group used TinyRCT for the first time, a previously undocumented backdoor designed to provide persistent access and control over compromised systems.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
...and registers a scheduled task to keep the infection alive across system reboots.
creates a scheduled task named GoogleUpdaterTaskSystem140.0.7272.0 set to run at the highest available privileges on every user login
TinyRCT's capabilities include arbitrary command execution, allowing attackers to run any command on the infected system.
The backdoor is designed to aid in spying on the system's users and allowing remote management and command execution via the shell
The backdoor and other components use file names similar to common system components to escape notice. TinyRCT masquerades as PerfWatson2.exe
Perhaps most concerning is the backdoor's self-destruct mechanism, which allows attackers to wipe evidence of their presence from the compromised system, complicating forensic analysis and incident response efforts.
TinyRCT, a lightweight C# backdoor, allows for arbitrary command execution, file exfiltration, screenshot capture, and self-deletion...
it's designed to evade sandboxes and other analysis tools by implementing an array of anti-analysis maneuvers
The backdoor is designed to aid in spying on the system's users and allowing remote management and command execution via the shell, configuration updates, and a variety of system fingerprinting
The malware uses hardcoded C2 addresses and AES-128 CBC encryption.
The C2 address is hardcoded at 45.32.113[.]172, communicating over plain HTTP with AES-128 CBC encryption
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A lightweight C# remote-access Trojan and backdoor used by CL-STA-1062 for espionage-oriented access. It supports remote shell command execution, configuration updates, system fingerprinting, spying on users, and data exfiltration, and includes anti-analysis and self-destruct capabilities. It masquerades as PerfWatson2.exe to evade detection.
A lightweight C# backdoor used for persistent access, arbitrary command execution, file exfiltration, screenshot capture, and self-deletion. It uses hardcoded C2 addresses and AES-128 CBC encryption, and is delivered via a malicious DLL disguised inside a legitimate-looking application installer.
A bespoke lightweight C# backdoor used by CL-STA-1062 for long-term, low-visibility persistence. It executes arbitrary commands, performs file and directory enumeration, exfiltrates files in encrypted chunks, captures screenshots, downloads files, creates persistence via a scheduled task, and can self-delete.
Custom .NET backdoor / remote access trojan used in attacks against Southeast Asian government and critical infrastructure targets. It supports arbitrary command execution, system and file reconnaissance, file upload and exfiltration, screenshot capture, remote control, self-deletion, sandbox evasion, and HTTP beaconing with AES-128-CBC encrypted communications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.