GOBLIN PANDA is a China-nexus threat actor tracked by CrowdStrike. Public reporting in the provided content places it among Chinese adversaries active in 2017 and 2020. The content states that GOBLIN PANDA used the Royal Road RTF weaponizer, also called the "8.t RTF exploit builder," which is shared among multiple targeted intrusion groups suspected of China involvement. Royal Road-generated documents exploit Microsoft Equation Editor vulnerabilities including CVE-2017-11882, CVE-2018-0798, and CVE-2018-0802, typically dropping an embedded object named "8.t" that is decoded to execute malware, including via DLL side-loading. The content also states that this adversary continued long-running operations against the government of Vietnam. CrowdStrike reporting cited in the content includes GOBLIN PANDA in China-nexus reporting for 2020, and separately notes that Chinese adversaries including GOBLIN PANDA rapidly adopted exploits such as CVE-2017-0199 and CVE-2017-8759 and targeted multiple sectors. No additional aliases or sub-groups are provided in the content beyond the lowercase form "goblin_panda."
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 malware family attributed to this actor across reporting.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named threat actor referenced in global threat reporting.
Targeted attack activity using Royal Road weaponized RTF documents exploiting Equation Editor vulnerabilities to execute payloads.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.