SongXY
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:18:07
Targeted industries: government-and-public-sector technology-and-telecommunications defense-and-aerospace
Context
SongXY is a Chinese APT group that employs phishing tactics to initiate cyberespionage campaigns. They utilize the Royal Road RTF builder, exploiting the CVE-2018-0798 vulnerability in Microsoft Equation Editor. In one instance, they sent a document containing a link to an attacker-controlled server, which automatically triggered upon opening, allowing them to gather information about the target's system configuration.
Exploited vulnerabilities
- CVE-2018-0798 (vulnerability)
Reports & references
- ptsecurity.com — Covid 19 And New Year Greetings The Higaisa Group (report)
- ptsecurity.com — Apt Attacks Eng (report)