logo

GOBLIN_PANDA__2020__Cycldek_Bridging_the_air_gap_Securelist.pdf

ID: 95752e9d-50bb-4e03-a52f-65bc46b8db26

STIX ID: report--95752e9d-50bb-4e03-a52f-65bc46b8db26

Threat Score

88/100

Uploaded: 2026-08-15

Published Date: 2020-06-04

Last Modified Date: 2020-06-04

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Kaspersky's analysis profiles Cycldek (Goblin Panda) as a sophisticated, long-running Chinese-speaking APT targeting Southeast Asian government and diplomatic networks, describes two operational clusters (BlueCore and RedCore) with distinct implants and shared resources, details a large lateral-movement and info-stealing toolset (including the previously unreported USBCulprit for USB-based exfiltration potentially targeting air-gapped systems), and publishes indicators of compromise and C2 infrastructure observed from 2018–2020.