TinyRCT is a previously undocumented lightweight C#/.NET remote access trojan and backdoor for Windows used by the Chinese-speaking threat cluster CL-STA-1062, which Palo Alto Networks Unit 42 assesses overlaps with Cisco Talos-tracked UAT-7237. It was first detected in 2025 and has been used in espionage-focused intrusions targeting government entities, military organizations, and critical infrastructure, including electricity, water, and state-owned energy organizations in Southeast Asia.
TinyRCT supports arbitrary command execution via cmd.exe, remote host management, system fingerprinting, directory and file enumeration, file reading and exfiltration, screenshot capture as JPEG, file download from URLs, configuration updates, and self-deletion. Unit 42 reported that it exfiltrates files in 40 KB gzip-compressed, AES-encrypted chunks. The malware includes anti-analysis and sandbox-evasion behavior, including terminating if not run from %LOCALAPPDATA%, and a self-destruct mechanism intended to remove forensic evidence; the self-delete routine uses choice.exe and removes its persistence scheduled task.
The malware communicates over plain HTTP with a hardcoded C2 at 45.32.113[.]172, uses AES-128-CBC encryption with the hardcoded key ThisIsASecretKey87654321, and defaults to a 10-second polling interval. Its code contains a Simplified Chinese string/comment in C2 parsing logic. Unit 42 found the payload hosted on attacker infrastructure at 139.180.134[.]221 as PerfWatson2.exe, a filename chosen to mimic the legitimate Microsoft Visual Studio telemetry component.
A documented delivery chain used a malicious archive named chrome_setup.zip containing a legitimate signed chrome_setup.exe, a malicious chrome_setup.exe.config, and a rogue MyAppDomainManager.dll. The .NET runtime loaded the rogue DLL via AppDomainManager injection inside the trusted chrome_setup.exe process. The loader checked for execution from the user Downloads directory, retrieved PerfWatson2.exe from staging infrastructure, dropped it into %LOCALAPPDATA%, and created a scheduled task named GoogleUpdaterTaskSystem140.0.7272.0 to run at user logon with the highest available privileges.
Associated indicators directly mentioned in the content include 139.180.134[.]221, 45.32.113[.]172, PerfWatson2.exe, chrome_setup.zip, MyAppDomainManager.dll, and the scheduled task name GoogleUpdaterTaskSystem140.0.7272.0.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A significant change, however, is that CL-STA-1062 now deploys a novel backdoor tool, known as TinyRCT. The researchers first detected the implant in 2025, describing it as small and stealthy with anti-analysis features, including a self-destruct mechanism that aims to delete forensic evidence.
A significant change, however, is that CL-STA-1062 now deploys a novel backdoor tool, known as TinyRCT. The researchers first detected the implant in 2025, describing it as small and stealthy with anti-analysis features, including a self-destruct mechanism that aims to delete forensic evidence.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
...and registers a scheduled task to keep the infection alive across system reboots.
creates a scheduled task named GoogleUpdaterTaskSystem140.0.7272.0 set to run at the highest available privileges on every user login
TinyRCT, a lightweight C# backdoor, allows for arbitrary command execution...
The backdoor is designed to aid in spying on the system's users and allowing remote management and command execution via the shell
The backdoor and other components use file names similar to common system components to escape notice. TinyRCT masquerades as PerfWatson2.exe
including a self-destruct mechanism that aims to delete forensic evidence
TinyRCT, a lightweight C# backdoor, allows for arbitrary command execution, file exfiltration, screenshot capture, and self-deletion...
it's designed to evade sandboxes and other analysis tools by implementing an array of anti-analysis maneuvers
The backdoor is designed to aid in spying on the system's users and allowing remote management and command execution via the shell, configuration updates, and a variety of system fingerprinting
The malware uses hardcoded C2 addresses and AES-128 CBC encryption.
The C2 address is hardcoded at 45.32.113[.]172, communicating over plain HTTP with AES-128 CBC encryption
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A lightweight C# remote-access Trojan and backdoor used by CL-STA-1062 for espionage-oriented access. It supports remote shell command execution, configuration updates, system fingerprinting, spying on users, and data exfiltration, and includes anti-analysis and self-destruct capabilities. It masquerades as PerfWatson2.exe to evade detection.
A lightweight C# backdoor used for persistent access, arbitrary command execution, file exfiltration, screenshot capture, and self-deletion. It uses hardcoded C2 addresses and AES-128 CBC encryption, and is delivered via a malicious DLL disguised inside a legitimate-looking application installer.
A bespoke lightweight C# backdoor used by CL-STA-1062 for long-term, low-visibility persistence. It executes arbitrary commands, performs file and directory enumeration, exfiltrates files in encrypted chunks, captures screenshots, downloads files, creates persistence via a scheduled task, and can self-delete.
Custom .NET backdoor / remote access trojan used in attacks against Southeast Asian government and critical infrastructure targets. It supports arbitrary command execution, system and file reconnaissance, file upload and exfiltration, screenshot capture, remote control, self-deletion, sandbox evasion, and HTTP beaconing with AES-128-CBC encrypted communications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.