8.t Dropper
Aliases: 8t_dropper, RoyalRoad
- First seen
- 2019-01-01 00:00:00
- Malware type
- dropper
- Profile updated
- 2026-07-07 12:38:52
Targeted industries: government-and-public-sector
Targeted regions: country_code:cn country_code:jp country_code:kr
Context
8T_Dropper has been used by Chinese threat actor TA428 in order to install Cotx RAT onto victim's machines during Operation LagTime IT. According to Proofpoint the attack was developed against a number of government agencies in East Asia overseeing government information technology, domestic affairs, foreign affairs, economic development, and political processes. The dropper was delivered through an RTF document exploiting CVE-2018-0798.
Detection coverage
- 9 YARA rules
Exploited vulnerabilities
- CVE-2017-11882 (vulnerability)
- CVE-2018-0798 (vulnerability)
Detection rules
- SEKOIA_Builder_Win_Royalroad_Rtf (yara-rule)
- SIGNATURE_BASE_Royalroad_Code_Pattern1 (yara-rule)
- SIGNATURE_BASE_Royalroad_Code_Pattern2 (yara-rule)
- SIGNATURE_BASE_Royalroad_Code_Pattern3 (yara-rule)
- SIGNATURE_BASE_Royalroad_Code_Pattern4Ab (yara-rule)
- SIGNATURE_BASE_Royalroad_Code_Pattern4Ce (yara-rule)
- SIGNATURE_BASE_Royalroad_Code_Pattern4D (yara-rule)
- SIGNATURE_BASE_Royalroad_RTF (yara-rule)
- MALPEDIA_Win_8T_Dropper_Auto (yara-rule)
Reports & references
- pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
- CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
- sentinelone.com — Targets Of Interest Russian Organizations Increasingly Under Attack By Chinese Apts (report)
- accenture.com — Accenture Security Mudcarp (report)
- proofpoint.com — Chinese Apt Operation Lagtime It Targets Government Information Technology (report)
- vb2020.vblocalhost.com — Vb2020 20 (report)
- research.checkpoint.com — Vicious Panda The Covid Campaign (report)
- Kaspersky — 97157 (report)
- medium.com — Malicious Document Targets Vietnamese Officials Acb3B9D8B80A (report)
- cdn-cybersecurity.att.com — Global Perspective Of The Sidewinder Apt (report)
- medium.com — Portdoor Malware Afc9D0796Cba (report)
- research.checkpoint.com — Pandas With A Soul Chinese Espionage Attacks Against Southeast Asian Government Entities (report)
- malpedia.caad.fkie.fraunhofer.de — Win.8T Dropper (report)
- tradahacking.vn — Another Malicious Document With Cve 2017 11882 839E9C0Bbf2F (report)
- virusbulletin.com — Vb2019 Paper Attribution Object Using Rtf Object Dimensions Track Apt Phishing Weaponizers (report)
- tradahacking.vn — L%C3%A0 1937Cn Hay Oceanlotus Hay Lazarus 6Ca15Fe1B241 (report)
- blog.malwarelab.pl — On The Royal Road (report)
- medium.com — New Version Of Chinoxy Backdoor Using Covid19 Document Lure 83Fa294C0746 (report)
- ics-cert.kaspersky.com — Kaspersky Ics Cert Apt Attacks On Industrial Organizations In H1 2021 En (report)
- go.recordedfuture.com — Cta 2022 0922 (report)
- nao-sec.org — Royal Road Redive (report)
- community.riskiq.com — 5Fe2Da7F (report)
- research.checkpoint.com — Rancor The Year Of The Phish (report)
- community.riskiq.com — 56Fa1B2F (report)
- malgamy.github.io — The Approach Of Ta413 For Tibetan Targets (report)