Royal Road! Re:Dive
ID: 721e44c2-a83e-52d1-a109-613d8a3b7efd
STIX ID: report--721e44c2-a83e-52d1-a109-613d8a3b7efd
Feed Name: Nao_Sec
This report surveys 2020 activity involving the China-linked Royal Road RTF weaponizer exploiting Microsoft Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802), documents new payload encodings, and attributes observed campaigns to multiple actors (Higaisa, Vicious Panda, FunnyDream, TA410) leveraging malware such as AttackBot, Chinoxy, and FlowCloud. It also describes a November 2020 Japan-focused intrusion delivering a previously unseen XLBug RAT with standard remote-control capabilities, and points to updated YARA rules, tooling, and IOC resources.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
