Royal Road is a malicious Rich Text Format (RTF) document builder and exploitation toolkit widely used in targeted cyberespionage campaigns by China-linked threat actors. It generates weaponized documents that exploit Microsoft Office Equation Editor vulnerabilities CVE-2017-11882, CVE-2018-0798, and CVE-2018-0802 to execute attacker-controlled code on Windows systems. Its documents embed encoded malware payloads that exploitation shellcode decodes and deploys, with multiple payload-encoding variants observed over time. The documents are commonly delivered through spearphishing emails, either as attachments or through links, using tailored social-engineering lures.
Royal Road is shared across multiple threat groups rather than uniquely associated with one operator. Documented users include Tonto Team, TA428, TA413, and RedFoxtrot. Its generated documents have delivered backdoors and downloaders including Bisonal, Poison Ivy, Cotx RAT, nccTrojan, LOWZERO, and Sepulcher. Campaigns using the toolkit have targeted government, diplomatic, defense, aerospace, telecommunications, and other organizations, as well as Tibetan civil society. Royal Road provides an initial exploitation and payload-delivery mechanism; subsequent remote access, persistence, credential theft, and information collection depend on the deployed malware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Royal Road ... allows the creation of malicious RTF files intended to exploit vulnerabilities in Microsoft Equation Editor (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
Royal Road ... allows the creation of malicious RTF files intended to exploit vulnerabilities in Microsoft Equation Editor (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
Royal Road ... allows the creation of malicious RTF files intended to exploit vulnerabilities in Microsoft Equation Editor (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
13 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Royal Road ... allows the creation of malicious RTF files intended to exploit vulnerabilities in Microsoft Equation Editor (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
The attackers used phishing emails to deliver malicious Microsoft Office documents created with the Royal Road Weaponizer.
Royal Road is a tool that generates RTF files that exploit the Microsoft Office Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
Royal Road is a tool that generates RTF files that exploit the Microsoft Office Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
Royal Road is a tool that generates RTF files that exploit the Microsoft Office Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
3 distinct techniques documented for this family, organized by ATT&CK tactic.
CERT-UA assessed that the documents... were likely built with the Royal Road builder and dropped the Bisonal backdoor.
Ensure Microsoft Office and Windows software are up to date with the latest software updates to protect against malicious documents that attempt to exploit known vulnerabilities for code execution, such as those created using the Royal Road RTF weaponizer.
21 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malicious document builder widely used by Chinese APT groups to craft phishing documents that exploit Microsoft Office vulnerabilities and deliver custom malware payloads such as Bisonal.
Offensive document-generation tool suspected of producing the malicious RTF documents used to deliver the Windows version of HZ RAT. The described RTF attack chain exploits a Microsoft Office Equation Editor vulnerability; attribution of document creation to Royal Road is tentative.
Malicious document builder used to create RTF exploits with plausible decoy content targeting Microsoft Equation Editor vulnerabilities. Tonto Team used its documents to deliver backdoors, a dropper, and a downloader in the attempted attacks against Group-IB.
A shared document-weaponization tool used by multiple Chinese state-sponsored groups. TA413 used it to create spearphishing RTF documents targeting Tibetan organizations. A May 2022 sample dropped an XOR-encoded payload that ultimately loaded LOWZERO; historical campaigns used Royal Road to load Sepulcher.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.