An Overhead View of the Royal Road
ID: 31db69e0-ee71-5a7d-9e14-8f8411d205d1
STIX ID: report--31db69e0-ee71-5a7d-9e14-8f8411d205d1
Feed Name: Nao_Sec
This report examines the Royal Road RTF weaponizer (aka the 8.t RTF exploit builder) and links its use to multiple China-linked threat actors and campaigns targeting primarily Asian organizations, including Japan. It explains how Royal Road leverages Microsoft Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802) to deploy payloads via the 8.t object, outlines attribution indicators (object/package patterns, encoding, filenames), highlights shared TTPs such as DLL sideloading and Office startup persistence, groups related actors (e.g., Tick, TA428, Tonto; Periscope, Conimes, Rancor), and references available IOCs to support hunting and detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
