8.t Dropper

Aliases: 8t_dropper, RoyalRoad

First seen
2019-01-01 00:00:00
Malware type
dropper
Profile updated
2026-07-07 12:38:52

Targeted industries: government-and-public-sector

Targeted regions: country_code:cn country_code:jp country_code:kr

Context

8T_Dropper has been used by Chinese threat actor TA428 in order to install Cotx RAT onto victim's machines during Operation LagTime IT. According to Proofpoint the attack was developed against a number of government agencies in East Asia overseeing government information technology, domestic affairs, foreign affairs, economic development, and political processes. The dropper was delivered through an RTF document exploiting CVE-2018-0798.

Detection coverage

  • 9 YARA rules

Exploited vulnerabilities

  • CVE-2017-11882 (vulnerability)
  • CVE-2018-0798 (vulnerability)

Detection rules

  • SEKOIA_Builder_Win_Royalroad_Rtf (yara-rule)
  • SIGNATURE_BASE_Royalroad_Code_Pattern1 (yara-rule)
  • SIGNATURE_BASE_Royalroad_Code_Pattern2 (yara-rule)
  • SIGNATURE_BASE_Royalroad_Code_Pattern3 (yara-rule)
  • SIGNATURE_BASE_Royalroad_Code_Pattern4Ab (yara-rule)
  • SIGNATURE_BASE_Royalroad_Code_Pattern4Ce (yara-rule)
  • SIGNATURE_BASE_Royalroad_Code_Pattern4D (yara-rule)
  • SIGNATURE_BASE_Royalroad_RTF (yara-rule)
  • MALPEDIA_Win_8T_Dropper_Auto (yara-rule)

Reports & references

  • pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
  • CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
  • sentinelone.com — Targets Of Interest Russian Organizations Increasingly Under Attack By Chinese Apts (report)
  • accenture.com — Accenture Security Mudcarp (report)
  • proofpoint.com — Chinese Apt Operation Lagtime It Targets Government Information Technology (report)
  • vb2020.vblocalhost.com — Vb2020 20 (report)
  • research.checkpoint.com — Vicious Panda The Covid Campaign (report)
  • Kaspersky — 97157 (report)
  • medium.com — Malicious Document Targets Vietnamese Officials Acb3B9D8B80A (report)
  • cdn-cybersecurity.att.com — Global Perspective Of The Sidewinder Apt (report)
  • medium.com — Portdoor Malware Afc9D0796Cba (report)
  • research.checkpoint.com — Pandas With A Soul Chinese Espionage Attacks Against Southeast Asian Government Entities (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.8T Dropper (report)
  • tradahacking.vn — Another Malicious Document With Cve 2017 11882 839E9C0Bbf2F (report)
  • virusbulletin.com — Vb2019 Paper Attribution Object Using Rtf Object Dimensions Track Apt Phishing Weaponizers (report)
  • tradahacking.vn — L%C3%A0 1937Cn Hay Oceanlotus Hay Lazarus 6Ca15Fe1B241 (report)
  • blog.malwarelab.pl — On The Royal Road (report)
  • medium.com — New Version Of Chinoxy Backdoor Using Covid19 Document Lure 83Fa294C0746 (report)
  • ics-cert.kaspersky.com — Kaspersky Ics Cert Apt Attacks On Industrial Organizations In H1 2021 En (report)
  • go.recordedfuture.com — Cta 2022 0922 (report)
  • nao-sec.org — Royal Road Redive (report)
  • community.riskiq.com — 5Fe2Da7F (report)
  • research.checkpoint.com — Rancor The Year Of The Phish (report)
  • community.riskiq.com — 56Fa1B2F (report)
  • malgamy.github.io — The Approach Of Ta413 For Tibetan Targets (report)

External references