Goblin Panda is a China-linked cyberespionage actor active since at least 2014, primarily targeting Southeast Asia, with a sustained focus on Vietnam's government. It is also tracked as Cycledek or Cycldek and has been associated with the 1937CN Team identity. Its activity has been observed in Vietnam, Cambodia, Indonesia, the Philippines, Myanmar, Malaysia, and Thailand, with additional limited targeting of India. Its operations align with Chinese geopolitical interests in the region. Goblin Panda commonly gains access through spearphishing attachments containing malicious Microsoft Office macros or exploits for vulnerabilities such as CVE-2012-0158 and CVE-2017-11882. It uses the Royal Road RTF weaponizer and DLL sideloading through legitimate applications to execute malicious payloads while evading detection. Observed infection chains establish persistence through registry Run keys, check for virtualized environments, and collect host and user information before retrieving additional payloads. Its malware includes PlugX, also known as Korplug, NewCore, and Sisfader. NewCore supports file collection and transfer, screen monitoring, remote command execution, and system-control functions. Goblin Panda is also associated with USBCulprit, which uses USB media to collect and transfer information from air-gapped Windows systems. Beyond espionage, Goblin Panda has been linked to politically motivated disruption in Vietnam. Vietnam's government attributed the July 2016 attacks on aviation systems to the group. Those attacks disrupted airport communications and passenger processing, displayed pro-China messages, defaced Vietnam Airlines' website, and exposed personal information belonging to more than 400,000 frequent-flyer members.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
Distribution of infected samples ... through weaponized Microsoft Office documents containing malicious macros, or by exploiting known vulnerabilities—most recently CVE-2012-0158 and CVE-2017-11882.
Distribution of infected samples ... through weaponized Microsoft Office documents containing malicious macros, or by exploiting known vulnerabilities—most recently CVE-2012-0158 and CVE-2017-11882.
RoyalRoad is a tool that generates weaponized RTF documents that exploit the following vulnerabilities in Microsoft’s Equation Editor: CVE-2017-11882, CVE-2018-0798 and CVE-2018-0802.
RoyalRoad is a tool that generates weaponized RTF documents that exploit the following vulnerabilities in Microsoft’s Equation Editor: CVE-2017-11882, CVE-2018-0798 and CVE-2018-0802.
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named threat actor referenced in global threat reporting.
Mentioned as another Chinese-linked group known to use RoyalRoad.
Mentioned only as an example of Chinese threat actor naming conventions in discussion of attribution.
Targeted attack activity using Royal Road weaponized RTF documents exploiting Equation Editor vulnerabilities to execute payloads.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.