TinyRCT backdoor with persistence, exfiltration, and self-deletion
Malware Activity
Summary
Hide ▲
Show ▼
The TinyRCT backdoor appeared in a 2025 intrusion operation, adding stealthy persistent access and control to the attackers' toolkit. It also supports command execution, file exfiltration, and screenshot capture, expanding post-compromise reach. A built-in self-destruct feature can wipe traces from infected systems and complicate response.
Related Happenings
GigaWiper / BLUERABBIT destructive Windows backdoor activity
Malware Activity
H score31
First: 09.07.2026 21:08
Last: 09.07.2026 21:08
Sources 1
About this happening:
The GigaWiper / BLUERABBIT malware activity now combines disk wiping, fake ransomware, and spyware backdoor functions on Windows, increasing the chance that on...
GigaWiper / BLUERABBIT destructive Windows backdoor activity
Malware ActivityAbout this happening: The GigaWiper / BLUERABBIT malware activity now combines disk wiping, fake ransomware, and spyware backdoor functions on Windows, increasing the chance that on...
TinyRCT backdoor used in CL-STA-1062 Southeast Asia intrusions
Malware Activity
H score15
First: 26.06.2026 19:21
Last: 26.06.2026 19:21
Sources 1
About this happening:
The newly documented TinyRCT backdoor gives CL-STA-1062 a custom remote-access payload for government and critical-infrastructure targets in Southeast Asia, expanding...
TinyRCT backdoor used in CL-STA-1062 Southeast Asia intrusions
Malware ActivityAbout this happening: The newly documented TinyRCT backdoor gives CL-STA-1062 a custom remote-access payload for government and critical-infrastructure targets in Southeast Asia, expanding...
CL-STA-1062 Southeast Asia critical infrastructure campaign using TinyRCT
Campaign
H score18
First: 26.06.2026 13:30
Last: 26.06.2026 13:30
Sources 1
How related:
A sustained campaign by a China-linked threat actor targeting government entities and critical infrastructure in Southeast Asia has been uncovered by researchers at Palo Alto Networks’ Unit 42.
About this happening:
A China-linked campaign by CL-STA-1062 is targeting government entities and critical infrastructure across Southeast Asia, with activity reaching state-owned...
CL-STA-1062 Southeast Asia critical infrastructure campaign using TinyRCT
CampaignHow related: A sustained campaign by a China-linked threat actor targeting government entities and critical infrastructure in Southeast Asia has been uncovered by researchers at Palo Alto Networks’ Unit 42.
About this happening: A China-linked campaign by CL-STA-1062 is targeting government entities and critical infrastructure across Southeast Asia, with activity reaching state-owned...
AppleChris, MemFun, and Getpass malware activity with persistent C2 and credential theft
Malware Activity
H score26
First: 13.03.2026 19:33
Last: 13.03.2026 19:33
Sources 1
About this happening:
The intrusion used AppleChris, MemFun, and Getpass to keep access on compromised Windows endpoints and steal credentials. The backdoors supported persistence,...
AppleChris, MemFun, and Getpass malware activity with persistent C2 and credential theft
Malware ActivityAbout this happening: The intrusion used AppleChris, MemFun, and Getpass to keep access on compromised Windows endpoints and steal credentials. The backdoors supported persistence,...
Remcos RAT variant with real-time surveillance and evasion
Malware Activity
H score28
First: 19.02.2026 18:30
Last: 19.02.2026 18:30
Sources 1
About this happening:
A newly observed Remcos RAT variant now enables real-time surveillance on compromised Windows systems, increasing the risk of immediate webcam monitoring and liv...
Remcos RAT variant with real-time surveillance and evasion
Malware ActivityAbout this happening: A newly observed Remcos RAT variant now enables real-time surveillance on compromised Windows systems, increasing the risk of immediate webcam monitoring and liv...
Timeline
-
25.06.2026 03:00 2 articles · 21d ago
CL-STA-1062 uses TinyRCT in Southeast Asia campaign
Technical Analysis UpdateCL-STA-1062 used TinyRCT for the first time in a 2025 campaign targeting state-owned enterprises and other critical infrastructure in Southeast Asia, adding a previously undocumented backdoor that provides persistent access, arbitrary command execution, file enumeration and exfiltration, screenshot capture, and a self-destruct mechanism.
Show sources
- China-Linked Hackers Strike Asian Critical Infrastructure with TinyRCT Backdoor — www.infosecurity-magazine.com — 26.06.2026 13:30
- China-Linked Hackers Strike Asian Critical Infrastructure with TinyRCT Backdoor — www.infosecurity-magazine.com — 26.06.2026 13:30