RoyalRoad is a weaponization kit used to generate malicious RTF documents that exploit Microsoft Equation Editor vulnerabilities, notably CVE-2017-11882, CVE-2018-0798, and CVE-2018-0802, to execute attacker-controlled payloads on Windows systems. It is widely associated with Chinese-linked espionage activity and has been used by multiple threat clusters including Sharp Panda (also tracked as Sharp Dragon), Tick, Tonto Team, TA428, Goblin Panda, and Rancor.
RoyalRoad is commonly employed in spearphishing operations in which victims receive government-themed or otherwise tailored lure documents. In some campaigns, a Word document using a remote template retrieves and launches a RoyalRoad-generated RTF as part of a staged infection chain. The kit has been observed delivering a range of follow-on malware, including downloaders, loaders, backdoors, and RATs such as PortDoor and FoundCore, as well as components used in the 5.t and Soul infection chains.
Operationally, RoyalRoad functions as an exploit builder rather than a conventional payload family. Its generated documents are designed to trigger Equation Editor flaws when opened, enabling initial code execution and handoff to subsequent malware. Variants have been observed with minor implementation changes, including altered temporary payload naming conventions, but the core role remains the same: weaponizing lure documents for initial compromise in targeted espionage campaigns. Victimology has included government, defense, military, diplomatic, healthcare, education, and related sectors, particularly in Southeast Asia, Africa, the Caribbean, Vietnam, and in at least one case a Russian defense contractor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
RoyalRoad is a tool that generates weaponized RTF documents that exploit the following vulnerabilities in Microsoft’s Equation Editor: CVE-2017-11882, CVE-2018-0798 and CVE-2018-0802.
RoyalRoad is a tool that generates weaponized RTF documents that exploit the following vulnerabilities in Microsoft’s Equation Editor: CVE-2017-11882, CVE-2018-0798 and CVE-2018-0802.
RoyalRoad is a tool that generates weaponized RTF documents that exploit the following vulnerabilities in Microsoft’s Equation Editor: CVE-2017-11882, CVE-2018-0798 and CVE-2018-0802.
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
RoyalRoad is a tool that generates weaponized RTF documents that exploit the following vulnerabilities in Microsoft’s Equation Editor: CVE-2017-11882, CVE-2018-0798 and CVE-2018-0802.
RoyalRoad is a tool that generates weaponized RTF documents that exploit the following vulnerabilities in Microsoft’s Equation Editor: CVE-2017-11882, CVE-2018-0798 and CVE-2018-0802.
RoyalRoad is a tool that generates weaponized RTF documents that exploit the following vulnerabilities in Microsoft’s Equation Editor: CVE-2017-11882, CVE-2018-0798 and CVE-2018-0802.
phishing documents leveraging a remote template weaponized using RoyalRoad
RoyalRoad is a tool that generates weaponized RTF documents that exploit the following vulnerabilities in Microsoft’s Equation Editor: CVE-2017-11882, CVE-2018-0798 and CVE-2018-0802.
RoyalRoad is a tool that generates weaponized RTF documents that exploit the following vulnerabilities in Microsoft’s Equation Editor: CVE-2017-11882, CVE-2018-0798 and CVE-2018-0802.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malicious RTF weaponizer/exploit builder used in spear-phishing to generate documents exploiting Microsoft Equation Editor flaws and drop payloads. In this case, a newer variant changed its usual dropped filename from "8.t" to "e.o" and ultimately delivered the PortDoor backdoor.
A malicious RTF weaponizer used to craft exploit-laden Word/RTF documents for delivery by Chinese-linked threat actors.
A malicious document weaponization tool used to craft phishing lures in the infection chain.
A malicious RTF exploit kit used in the phishing-based initial infection chain to deliver the downloader stage.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.