logo

GOBLIN_PANDA__2018__Goblin_Panda_against_Bears.pdf

ID: 110f67c6-40cd-47d9-bcfe-fde18ff06668

STIX ID: report--110f67c6-40cd-47d9-bcfe-fde18ff06668

Threat Score

75/100

Uploaded: 2026-08-15

Published Date: 2018-08-21

Last Modified Date: 2018-08-21

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Goblin Panda (APT) used RTF exploitation (CVE-2017-11882) to deploy the Sisfader RAT against telecom targets; the report provides assembly-level analysis of anti-emulation checks, a rolling XOR decryption loop for config, persistence via service/COM object hijack, and enumerates IOCs (file hashes, domains, IP addresses) linking the infrastructure to known APT activity.