Conimes is a targeted intrusion threat actor associated with the use of the Royal Road RTF weaponizer, also known as the 8.t RTF exploit builder. It has been grouped with Periscope and Rancor in a cluster of operators that shared techniques and were active during the same period, indicating tooling or tradecraft overlap. This cluster has been assessed as focusing on Southeast Asia. Conimes has been linked to spearphishing-style initial access using malicious RTF documents weaponized to exploit Microsoft Equation Editor vulnerabilities including CVE-2017-11882, CVE-2018-0798, and CVE-2018-0802. Royal Road-generated documents associated with this activity typically deliver an embedded object that is decoded and used to launch follow-on malware. Observed execution tradecraft includes DLL side-loading. The actor’s activity is part of a broader ecosystem of targeted attack groups using Royal Road, a tool widely associated with suspected China-nexus intrusion activity. Known alias usage in the available reporting is limited to Conimes. Conimes is notable less for a uniquely documented malware family than for its participation in a technique-sharing cluster defined by common RTF weaponization characteristics, exploit delivery patterns, and related post-exploitation execution methods.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.