GOBLIN PANDA
Also reported as Cycldek, Conimes, 1937CN and Goblin Panda. Linked to China by three sources.
Reports per quarter
CVEs named in reports
- CVE-2006-3439
- CVE-2008-4250 KEV
- CVE-2010-2568 KEV
- CVE-2010-2729
- CVE-2010-2743
- CVE-2010-2772
- CVE-2010-3333 KEV
- CVE-2010-3338
- CVE-2012-0158 KEV ransomware
- CVE-2012-1856 KEV
- CVE-2012-3015
- CVE-2012-4792 KEV
Show all 70 CVEs Show fewer
- CVE-2014-0160 KEV
- CVE-2014-0322 KEV
- CVE-2014-1761 KEV
- CVE-2014-1776 KEV
- CVE-2014-4113 KEV
- CVE-2014-6271 KEV
- CVE-2014-6277
- CVE-2014-6278 KEV
- CVE-2014-7169 KEV
- CVE-2014-7186
- CVE-2014-7187
- CVE-2015-0096
- CVE-2015-5119 KEV
- CVE-2015-5122 KEV
- CVE-2015-6585
- CVE-2015-7645 KEV ransomware
- CVE-2016-1019 KEV ransomware
- CVE-2016-4117 KEV ransomware
- CVE-2017-0144 KEV ransomware
- CVE-2017-0199 KEV ransomware
- CVE-2017-11882 KEV ransomware
- CVE-2017-12824
- CVE-2017-15399
- CVE-2017-1882
- CVE-2017-8291 KEV
- CVE-2017-8464 KEV
- CVE-2017-8570 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-13379 KEV ransomware
- CVE-2018-8174 KEV ransomware
- CVE-2018-8345
- CVE-2018-8346
- CVE-2018-8570
- CVE-2018-8641
- CVE-2018-8653 KEV
- CVE-2019-10149 KEV
- CVE-2019-11510 KEV ransomware
- CVE-2019-1188
- CVE-2019-1280
- CVE-2019-1367 KEV ransomware
- CVE-2019-1429 KEV
- CVE-2019-1652 KEV
- CVE-2019-1653 KEV
- CVE-2019-19781 KEV ransomware
- CVE-2019-2215 KEV
- CVE-2019-9670 KEV
- CVE-2020-0674 KEV
- CVE-2020-0684
- CVE-2020-0729
- CVE-2020-0796 KEV ransomware
- CVE-2020-10189 KEV
- CVE-2020-1299
- CVE-2020-1421
- CVE-2021-1732 KEV ransomware
- CVE-2021-22941 KEV ransomware
- CVE-2022-26134 KEV ransomware
- CVE-2022-41091 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
CrowdCasts Monthly: You Have an Adversary Problem
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CrowdCasts Monthly: You Have an Adversary Problem
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor FlawedAmmyy (Malware Family)
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor eset_jumping_the_air_gap_wp
Show all 86 reports Show fewer
-
Chinese Cyberspies Target Military Organizations in Asia With New Malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Chinese Cyberspies Target Military Organizations in Asia With New Malware
-
APT_trends_report_Q1_2021_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q1_2021_Securelist
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q1 2021
-
The leap of a Cycldek-related threat actor
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The leap of a Cycldek-related threat actor
-
COVID-19 Phishing With a Side of Cobalt Strike
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor COVID-19 Phishing With a Side of Cobalt Strike
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor nao-sec.org-Royal Road ReDive
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Royal Road! Re-Dive
-
Group-IB_Hi-Tech_Crime_Trends_2020-2021_en
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2020-2021_en
-
Cycldek aka Goblin Panda- Chronicles of the Goblin
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cycldek aka Goblin Panda- Chronicles of the Goblin
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor IT threat evolution Q2 2020
-
Cycldek- Bridging the (air) gap
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cycldek- Bridging the (air) gap
-
Cycldek_ Bridging the (air) gap _ Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Cycldek_ Bridging the (air) gap _ Securelist
-
Attribution is in the object- using RTF object dimensions to track APT phishing weaponizers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Attribution is in the object- using RTF object dimensions to track APT phishing weaponizers
-
Goblin Panda APT- Recent infrastructure and RAT analysis
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Goblin Panda APT- Recent infrastructure and RAT analysis
-
An Overhead View of the Royal Road
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor An Overhead View of the Royal Road
-
Cyber Threat Landscape in Japan – Revealing Threat in the Shadow
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cyber Threat Landscape in Japan – Revealing Threat in the Shadow
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor [CB19] Cyber Threat Landscape in Japan – Revealing Threat in the Shadow by Chi En Shen (Ashley) Oleg Bondarenko
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Rancor- The Year of The Phish
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Multiple Chinese Threat Groups Exploiting CVE-2018-0798 Equation Editor Vulnerability Since Late 2018
-
Into the Fog - The Return of ICEFOG APT
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Into the Fog - The Return of ICEFOG APT
-
Into the Fog - The Return of ICEFOG APT
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Into the Fog - The Return of ICEFOG APT
-
Reaver- Mapping Connections Between Disparate Chinese APT Groups
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Reaver- Mapping Connections Between Disparate Chinese APT Groups
-
Chineses Actor APT target Ministry of Justice Vietnamese
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Chineses Actor APT target Ministry of Justice Vietnamese
-
Goblin Panda continues to target Vietnam
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Goblin Panda continues to target Vietnam
-
Analyzing Digital Quartermasters in Asia – Do Chinese and Indian APTs Have a Shared Supply Chain?
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Analyzing Digital Quartermasters in Asia – Do Chinese and Indian APTs Have a Shared Supply Chain?
-
Goblin Panda changes the dropper and reuses the old infrastructure
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Goblin Panda changes the dropper and reuses the old infrastructure
-
Là 1937CN hay OceanLotus hay Lazarus …
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Là 1937CN hay OceanLotus hay Lazarus …
-
CTA Adversary Playbook- Goblin Panda
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor CTA Adversary Playbook- Goblin Panda
-
Malicious document targets Vietnamese officials
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Malicious document targets Vietnamese officials
-
Goblin Panda targets Cambodia sharing capacities with another Chinese group hackers Temp Periscope
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Goblin Panda targets Cambodia sharing capacities with another Chinese group hackers Temp Periscope
-
Meet CrowdStrike’s Adversary of the Month for August- GOBLIN PANDA
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Meet CrowdStrike’s Adversary of the Month for August- GOBLIN PANDA
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Goblin_Panda_against_Bears
-
Goblin Panda against the Bears
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Goblin Panda against the Bears
-
Malicious document targets Vietnamese officials – Sebdraven – Medium
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Malicious document targets Vietnamese officials – Sebdraven – Medium
-
Malicious document targets Vietnamese officials
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Malicious document targets Vietnamese officials
-
Rehashed RAT Used in APT Campaign Against Vietnamese Organizations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Rehashed RAT Used in APT Campaign Against Vietnamese Organizations
-
Rhetoric Foreshadows Cyber Activity in the South China Sea
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Rhetoric Foreshadows Cyber Activity in the South China Sea
-
The Msnmm Campaigns: The Earliest Naikon APT Campaigns
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Msnmm Campaigns: The Earliest Naikon APT Campaigns
-
2015-05-29 -The MsnMM Campaigns - The Earliest Naikon APT Campaigns
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2015-05-29 -The MsnMM Campaigns - The Earliest Naikon APT Campaigns
-
The Chronicles Of The Hellsing APT: The Empire Strikes Back
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Chronicles Of The Hellsing APT: The Empire Strikes Back
-
The Chronicles of the Hellsing APT- the Empire Strikes Back
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Chronicles of the Hellsing APT- the Empire Strikes Back
-
The Chronicles of the Hellsing APT_the Empire Strikes Back
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Chronicles of the Hellsing APT_the Empire Strikes Back
-
Elite cyber crime group strikes back after attack by rival APT gang
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Elite cyber crime group strikes back after attack by rival APT gang
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Global Threat Intel Report
-
CrowdCasts Monthly- You Have an Adversary Problem
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor CrowdCasts Monthly- You Have an Adversary Problem
-
CrowdCasts Monthly: You Have an Adversary Problem
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CrowdCasts Monthly: You Have an Adversary Problem
Newest first. Details opens the report in Explore.