TinyRCT
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Analysis of the binary's internal strings revealed that the authors refer to this tool as TinyRCT. TinyRCT is a lightweight, C#-based remote access Trojan (RAT) targeting Windows. It operates as a backdoor, enabling attackers to execute arbitrary system commands, exfiltrate files, capture screenshots and remotely manage the infected host.
Government entities and critical infrastructure were targeted for espionage in SE Asia by attackers using a hybrid toolkit, including custom TinyRCT backdoor.
Techniques & procedures
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Execution
3 techniques
Execution
The task is configured to run the malware with the highest available privileges (e.g., /rl highest ) every time the user logs on to the system (e.g., /sc onlogon ). This ensures that the infection survives system reboots.
Persistence
1 technique
Persistence
Privilege Escalation
1 technique
Privilege Escalation
Stealth
4 techniques
Stealth
These tools were often disguised as legitimate system files, such as VMware executables or an XDR agent.
Upon receiving the self-destruct command, the malware first deletes the GoogleUpdater scheduled task created by the loader. It then executes a self-deletion routine
Upon execution, the malware performs an environment validation to explicitly verify that it was executed from %LOCALAPPDATA% . If the malware was executed from any other location – such as a sandbox environment or a malware analyst’s desktop – the binary terminates immediately.
Discovery
5 techniques
Discovery
Host Fingerprinting and Registration Before entering its main command loop, TinyRCT conducts initial reconnaissance to fingerprint the infected host... collecting the following data points: ... Local IP addresses
TinyRCT conducts initial reconnaissance to fingerprint the infected host... collecting the following data points: User and system context: Current username, machine name and OS version.
As part of our observations of CL-STA-1062, we noted activity sending the results of network and system enumeration directly to an actor-controlled IP address using curl.
File listing: Enumerates directories and files in the specified path. Returns format: Filename*Date*Size .
Upon execution, the malware performs an environment validation to explicitly verify that it was executed from %LOCALAPPDATA% . If the malware was executed from any other location – such as a sandbox environment or a malware analyst’s desktop – the binary terminates immediately.
Collection
1 technique
Collection
IOCs tracked for this family
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A custom backdoor used as part of a hybrid toolkit in espionage operations targeting government entities and critical infrastructure in Southeast Asia.
A previously undocumented .NET/C# remote access trojan used as a backdoor. It fingerprints hosts, registers to C2 over HTTP with AES-128-CBC encrypted traffic, executes commands, lists and reads files, downloads files, exfiltrates files in chunks, captures screenshots, persists via scheduled task, and supports self-deletion.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.