logo

An Overhead View of the Royal Road

ID: 31db69e0-ee71-5a7d-9e14-8f8411d205d1

STIX ID: report--31db69e0-ee71-5a7d-9e14-8f8411d205d1

Feed Name: Nao_Sec

Threat Score

Date Published: 2020-01-29

Date Updated: 2026-03-24

Author: nao_sec

...
...

This report examines the Royal Road RTF weaponizer (aka the 8.t RTF exploit builder) and links its use to multiple China-linked threat actors and campaigns targeting primarily Asian organizations, including Japan. It explains how Royal Road leverages Microsoft Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802) to deploy payloads via the 8.t object, outlines attribution indicators (object/package patterns, encoding, filenames), highlights shared TTPs such as DLL sideloading and Office startup persistence, groups related actors (e.g., Tick, TA428, Tonto; Periscope, Conimes, Rancor), and references available IOCs to support hunting and detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.