GOBLIN_PANDA__2018__Goblin_Panda_against_Bears.pdf
ID: 110f67c6-40cd-47d9-bcfe-fde18ff06668
STIX ID: report--110f67c6-40cd-47d9-bcfe-fde18ff06668
Threat Score
75/100
Uploaded: 2026-08-15
Published Date: 2018-08-21
Last Modified Date: 2018-08-21
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Goblin Panda (APT) used RTF exploitation (CVE-2017-11882) to deploy the Sisfader RAT against telecom targets; the report provides assembly-level analysis of anti-emulation checks, a rolling XOR decryption loop for config, persistence via service/COM object hijack, and enumerates IOCs (file hashes, domains, IP addresses) linking the infrastructure to known APT activity.
