GOBLIN_PANDA__2020__Cycldek_Bridging_the_air_gap_Securelist.pdf
ID: 95752e9d-50bb-4e03-a52f-65bc46b8db26
STIX ID: report--95752e9d-50bb-4e03-a52f-65bc46b8db26
Threat Score
88/100
Uploaded: 2026-08-15
Published Date: 2020-06-04
Last Modified Date: 2020-06-04
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Kaspersky's analysis profiles Cycldek (Goblin Panda) as a sophisticated, long-running Chinese-speaking APT targeting Southeast Asian government and diplomatic networks, describes two operational clusters (BlueCore and RedCore) with distinct implants and shared resources, details a large lateral-movement and info-stealing toolset (including the previously unreported USBCulprit for USB-based exfiltration potentially targeting air-gapped systems), and publishes indicators of compromise and C2 infrastructure observed from 2018–2020.
