Royal Road is a malicious Rich Text Format weaponizer used to generate lure documents for targeted intrusion campaigns. It is best known for building RTF files that exploit Microsoft Office Equation Editor vulnerabilities including CVE-2017-11882, CVE-2018-0798, and CVE-2018-0802, then decode and launch embedded payloads through shellcode. The builder is commonly associated with Chinese espionage operations and has been repeatedly observed as shared tooling across multiple China-linked threat clusters rather than being exclusive to a single actor.
Royal Road has been used extensively in spearphishing operations against government, defense, aerospace, telecommunications, education, healthcare, energy, manufacturing, mining, research, and other sensitive sectors, especially in East Asia, Central Asia, South Asia, Russia, Mongolia, Pakistan, and parts of Europe. Document themes commonly impersonate official correspondence, policy material, resumes, summit invitations, labor matters, public health guidance, and other topical lures tailored to the victim.
Operationally, Royal Road produces weaponized RTF attachments that exploit Equation Editor flaws and carry encoded malware objects, historically including an object commonly named 8.t. After exploitation, shellcode decodes the embedded payload and executes follow-on malware. Multiple payload encodings have been documented, including both long-observed and newer variants, indicating continued maintenance and adaptation of the builder. Related samples lacking the classic embedded object naming convention have also been tied to the same tooling lineage.
Royal Road has delivered a wide range of second-stage malware, including Poison Ivy, Cotx RAT, Bisonal, AttackBot, Chinoxy, FlowCloud, IceFog, NewCore RAT, Tmanger, nccTrojan, and other remote-access or downloader components. Campaigns using Royal Road have also led to broader post-compromise activity such as credential theft, reconnaissance, lateral movement, persistence, and file exfiltration once follow-on implants were established.
Threat reporting has linked Royal Road use to numerous Chinese or China-linked groups, including TA428, Tonto Team, Earth Akhlut, TA410, Higaisa, FunnyDream, Vicious Panda, Temp.Conimes, Naikon, TA413, RedFoxtrot, and other unidentified operators. Its prevalence across otherwise distinct intrusion sets makes it a notable example of shared offensive tooling within the Chinese espionage ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Royal Road is a tool that generates RTF files that exploit the Microsoft Office Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
Royal Road is a tool that generates RTF files that exploit the Microsoft Office Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
Royal Road is a tool that generates RTF files that exploit the Microsoft Office Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
11 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Royal Road is a tool that generates RTF files that exploit the Microsoft Office Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
Royal Road is a tool that generates RTF files that exploit the Microsoft Office Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
Royal Road is a tool that generates RTF files that exploit the Microsoft Office Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
Royal Road is a tool that generates RTF files that exploit the Microsoft Office Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
Royal Road is a tool that generates RTF files that exploit the Microsoft Office Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
Royal Road is a tool that generates RTF files that exploit the Microsoft Office Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
3 distinct techniques documented for this family, organized by ATT&CK tactic.
CERT-UA assessed that the documents... were likely built with the Royal Road builder and dropped the Bisonal backdoor.
Ensure Microsoft Office and Windows software are up to date with the latest software updates to protect against malicious documents that attempt to exploit known vulnerabilities for code execution, such as those created using the Royal Road RTF weaponizer.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malicious document builder widely used by Chinese APT groups to craft phishing documents that exploit Microsoft Office vulnerabilities and deliver custom malware payloads such as Bisonal.
Royal Road is a malicious document builder used to craft weaponized RTF and Office documents that exploit vulnerabilities in Microsoft Office. It is widely used by Chinese APT groups to deliver various payloads, including Bisonal. The builder automates the creation of documents that exploit n-day vulnerabilities for initial access.
RTF weaponization builder used to generate exploit documents (e.g., Equation Editor exploitation) for initial execution in Downloader.Climax.B delivery; tool commonly associated with Asian APT activity.
An RTF weaponizer tool referenced as historically used by Indian and Chinese APT actors to generate weaponized RTF documents for malicious delivery (e.g., phishing).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.