SongXY

Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:18:07

Targeted industries: government-and-public-sector technology-and-telecommunications defense-and-aerospace

Context

SongXY is a Chinese APT group that employs phishing tactics to initiate cyberespionage campaigns. They utilize the Royal Road RTF builder, exploiting the CVE-2018-0798 vulnerability in Microsoft Equation Editor. In one instance, they sent a document containing a link to an attacker-controlled server, which automatically triggered upon opening, allowing them to gather information about the target's system configuration.

Exploited vulnerabilities

  • CVE-2018-0798 (vulnerability)

Reports & references

  • ptsecurity.com — Covid 19 And New Year Greetings The Higaisa Group (report)
  • ptsecurity.com — Apt Attacks Eng (report)

External references