Periscope is a targeted intrusion group associated with the use of the Royal Road RTF weaponizer, a document-based exploit builder widely seen in suspected China-nexus espionage operations. Periscope has been clustered with Conimes and Rancor as part of a group of operators focused on Southeast Asia, with reporting noting technique overlap and contemporaneous activity among those actors. The group’s operations are linked to spearphishing-style initial access using malicious RTF documents that exploit Microsoft Equation Editor vulnerabilities, including CVE-2017-11882, CVE-2018-0798, and CVE-2018-0802. These lures commonly deliver embedded content that is decoded and used to launch follow-on malware, including execution chains involving DLL side-loading. Periscope’s observed tradecraft therefore includes initial access through weaponized documents, post-exploitation payload execution, and defense-evasion or execution techniques associated with DLL side-loading. Available evidence in this context supports characterization of Periscope as an espionage-oriented actor operating within a broader ecosystem of Royal Road-sharing intrusion groups.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.