Goblin Panda is a China-linked cyber-espionage threat actor widely associated with operations aligned to Chinese state interests. The group is also referred to by some vendors as 1937CN, and public reporting has at times treated the two names as effectively interchangeable. Goblin Panda has been repeatedly linked to long-running operations against Vietnam and other Asian targets, particularly in politically sensitive contexts involving regional disputes and state interests. The actor is known for spear-phishing-led intrusions using malicious document lures, including RoyalRoad-generated RTF files that exploit Microsoft Equation Editor vulnerabilities such as CVE-2017-11882, CVE-2018-0798, and CVE-2018-0802. Reported tradecraft includes use of decoy documents themed around government or policy matters, DLL side-loading or search-order hijacking with legitimate signed executables, process injection, persistence via scheduled tasks or Office startup mechanisms, and deployment of remote access tooling for follow-on espionage. Goblin Panda has been associated in reporting with malware and tooling such as Chinoxy, PivNoxy, PoisonIvy, PortDoor, and USB-based air-gap intrusion activity tracked as USBCulprit. The group has also been cited among China-nexus operators known to use the RoyalRoad weaponizer. Victimology centers on government and public-sector entities, with especially strong reporting on sustained targeting of Vietnam. Public reporting also places the actor in campaigns affecting telecommunications and defense-related targets in Asia and in activity overlapping broader China-aligned intrusion ecosystems. Goblin Panda has been connected to operations against Vietnamese government and aviation entities, including disruptive and data-compromise activity in 2016, and to later COVID-19-themed targeting of Vietnam. Additional references place the actor within broader China-linked targeting patterns involving South and Southeast Asia. Goblin Panda’s operational behavior is consistent with espionage-focused collection: reconnaissance on compromised hosts, remote command execution, payload retrieval, information theft, and in some cases lateral movement enabled by backdoor access. The actor’s repeated use of Chinese-associated tooling, infrastructure patterns, and targeting aligned with PRC geopolitical priorities supports assessment of a China nexus.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
RoyalRoad is a tool that generates weaponized RTF documents that exploit the following vulnerabilities in Microsoft’s Equation Editor: CVE-2017-11882, CVE-2018-0798 and CVE-2018-0802.
RoyalRoad is a tool that generates weaponized RTF documents that exploit the following vulnerabilities in Microsoft’s Equation Editor: CVE-2017-11882, CVE-2018-0798 and CVE-2018-0802.
RoyalRoad is a tool that generates weaponized RTF documents that exploit the following vulnerabilities in Microsoft’s Equation Editor: CVE-2017-11882, CVE-2018-0798 and CVE-2018-0802.
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named threat actor referenced in global threat reporting.
Mentioned as another Chinese-linked group known to use RoyalRoad.
Mentioned only as an example of Chinese threat actor naming conventions in discussion of attribution.
Targeted attack activity using Royal Road weaponized RTF documents exploiting Equation Editor vulnerabilities to execute payloads.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.