Cycldek is a suspected Chinese-speaking cyber espionage threat actor, also known as Goblin Panda, APT 27, and Conimes. Reporting in the provided content states the group has targeted governments in Southeast Asia since 2013, with later activity affecting diplomatic and government targets in Vietnam and Laos, and broader targeting of high-profile Vietnamese organizations, including government, military, health, diplomacy, education, and political sectors. The content also notes occasional targeting in Central Asia and Thailand. Cycldek has been associated with politically themed phishing emails delivering malicious RTF documents exploiting known vulnerabilities, including RoyalRoad-generated documents exploiting CVE-2018-0802. The group is linked in the content to DLL side-loading infection chains, including use of legitimate executables with malicious side-loaded DLLs and encoded payloads. Malware and tooling associated with Cycldek in the provided content include NewCore RAT, including BlueCore and RedCore variants; FoundCore, a remote administration tool providing filesystem and process manipulation, screenshot capture, and arbitrary command execution; CoreLoader; DropPhone; and RedCore Loader. FoundCore is described as establishing persistence via a Windows service, setting an empty DACL on its process image, and communicating with command-and-control over RC4-encrypted raw TCP or HTTPS. The content also states Cycldek toolchains include USBCulprit, which uses USB media to exfiltrate data and may indicate attempts to reach air-gapped networks. The provided reporting links some 2020-2021 intrusions to Cycldek with low confidence based on code similarities between CoreLoader or FoundCore and Cycldek-associated tooling, notably RedCore Loader. Separate reporting cited in the content says activity tracked by Kaspersky as FoundCore was attributed to Cycldek. The content also notes use of PCShare in campaigns attributed to Cycldek.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
14 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Chinese-speaking threat group referenced in attribution of the FoundCore/RainyDay-related activity; mentioned as a possible tracker attribution for the same tooling/ecosystem around the PlugX variant and RainyDay configuration structure.
Low-confidence attribution for a June 2020–Jan 2021 campaign primarily targeting Vietnam (government/military and related sectors). Activity includes RoyalRoad-generated RTF exploitation (CVE-2018-0802) leading to a multi-stage chain (DropPhone/CoreLoader/FoundCore) and a FoundCore RAT with persistence and C2 over RC4-encrypted TCP or HTTPS.
Espionage actor targeting Southeast Asian governments; uses politically themed phishing with weaponized RTFs exploiting known vulnerabilities, deploys NewCore RAT variants, and uses USB-based tooling (USBCulprit) to exfiltrate data and potentially reach air-gapped networks.
Chinese cyber espionage group referenced as having used PCShare in campaigns targeting Southeast Asian governments.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.