RoyalRoad is an RTF exploit builder and payload-delivery tool, also known as the 8.t Dropper, used by multiple China-linked cyberespionage groups. It generates weaponized documents that exploit Microsoft Equation Editor vulnerabilities CVE-2017-11882, CVE-2018-0798, and CVE-2018-0802 to execute attacker-controlled code on vulnerable Windows systems. Its documents drop and execute additional malware, with observed infection chains delivering downloaders and backdoors including PortDoor, VictoryDLL, the Soul framework, and FoundCore.
RoyalRoad-generated documents are commonly distributed through targeted phishing emails, either as malicious RTF attachments or through Word documents that retrieve weaponized RTF files using remote templates. Lures frequently imitate government correspondence or use diplomatic and defense-related themes. Observed deployment mechanisms include installing a malicious Word add-in for persistence and launching a dropped downloader through a scheduled task.
RoyalRoad has been used by Tick, Tonto Team, TA428, Goblin Panda, Rancor, and Sharp Panda, also known as Sharp Dragon. Campaigns have targeted government and diplomatic organizations, particularly in Southeast Asia, as well as Russian defense organizations and international government officials. Because multiple threat actors share the tool, its presence alone does not establish attribution to a specific group.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Niranjan Jayanand, threat hunting manager for the Asia-Pacific region at SentinelOne WatchTower, told Information Security Media Group the attackers used the RoyalRoad builder tool to craft the RTF file.
RoyalRoad is a tool that generates weaponized RTF documents that exploit the following vulnerabilities in Microsoft’s Equation Editor: CVE-2017-11882, CVE-2018-0798 and CVE-2018-0802.
RoyalRoad is a tool that generates weaponized RTF documents that exploit the following vulnerabilities in Microsoft’s Equation Editor: CVE-2017-11882, CVE-2018-0798 and CVE-2018-0802.
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Niranjan Jayanand, threat hunting manager for the Asia-Pacific region at SentinelOne WatchTower, told Information Security Media Group the attackers used the RoyalRoad builder tool to craft the RTF file.
RoyalRoad is a tool that generates weaponized RTF documents that exploit the following vulnerabilities in Microsoft’s Equation Editor: CVE-2017-11882, CVE-2018-0798 and CVE-2018-0802.
RoyalRoad is a tool that generates weaponized RTF documents that exploit the following vulnerabilities in Microsoft’s Equation Editor: CVE-2017-11882, CVE-2018-0798 and CVE-2018-0802.
RoyalRoad is a tool that generates weaponized RTF documents that exploit the following vulnerabilities in Microsoft’s Equation Editor: CVE-2017-11882, CVE-2018-0798 and CVE-2018-0802.
phishing documents leveraging a remote template weaponized using RoyalRoad
RoyalRoad is a tool that generates weaponized RTF documents that exploit the following vulnerabilities in Microsoft’s Equation Editor: CVE-2017-11882, CVE-2018-0798 and CVE-2018-0802.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An exploit-building tool used to weaponize RTF documents for spear-phishing attacks. In the reported G7 campaign, attackers used it to craft documents exploiting CVE-2017-11882 in Microsoft Office and deploy an unnamed information stealer. The article also describes historical RoyalRoad use against a defense contractor and by Tonto Team against Group-IB employees. The G7 attacks were not attributed to a specific APT group.
A malicious RTF weaponizer/exploit builder used in spear-phishing to generate documents exploiting Microsoft Equation Editor flaws and drop payloads. In this case, a newer variant changed its usual dropped filename from "8.t" to "e.o" and ultimately delivered the PortDoor backdoor.
A malicious RTF weaponizer used to craft exploit-laden Word/RTF documents for delivery by Chinese-linked threat actors.
A malicious document weaponization tool used to craft phishing lures in the infection chain.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.