Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors SongXY

Also known as: Sakaguchi S, Akiba H, et al, CLEC5A-HER2, online supplemental figure S4, cpyy, APT3, Gothic Panda, UPS Team, TG-0110, DeputyDog, Parastoo, Newscaster, APT28, Pawn Storm, Fancy Bear, Sednit, MiniDionis, Hammertoss, Chinastrats, Patchwork

Description

SongXY is believed to be an advanced persistent threat unit operating out of China that focuses on corporate espionage and state‑level intelligence gathering. Their typical attack chain begins with a spear‑phishing email that advertises or directly includes a malicious RTF file. When the victim opens this document, it exploits the Equation Editor flaw (CVE‑2018‑0798), allowing execution of arbitrary code under the user's privileges. The group leverages the Royal Road RTF builder tool to construct documents that embed the exploit payload seamlessly, exploiting the social engineering angle to increase click‑through rates. Once executed, the attacker can gather system configuration details—such as installed software, user accounts, and network settings—and potentially deploy additional backdoors or exfiltration agents. Although SongXY’s campaigns appear opportunistic in terms of sector, they tend to target assets containing strategic value like research data, defense secrets, financial records, and infrastructure control systems. The absence of large‑scale malware families in the public record suggests a more tailored and low‑profile approach compared to better‑known APTs such as APT28 or APT41. The threat actor’s catalog of aliases—ranging from Sakaguchi S and Akiba H to “Newscaster” and “Apt3”—often overlaps with other Chinese groups, which may obscure attribution efforts. Nevertheless, the consistent use of the Equation Editor exploit and spear‑phishing via RTF documents is a distinguishing signature. Finally, SongXY’s operational tempo appears moderate; incidents have surfaced sporadically over the past few years with no obvious coordinated multi‑phase campaigns detected so far.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Non profit
Media
Telecommunications
Energy
Aerospace
Education
Information technology
Maritime
Manufacturing
Think tank
Healthcare
Pharmaceutical
Chemical
Mining
Critical infrastructure
Hospitality
Legal services
Nuclear
Entertainment

Targeted Countries / Regions

US
CN
IN
GB
JP
DE
KR
IR
RU
SA
TW
FR
CA
IL
TR
VN
AU
KZ
PK
UA
PL
AE
SG
NL
BR
ES
IQ
BY
IT
SY
MX
RO
EG
AZ

AI Analysis

Grounded in web research
· 13 hours ago

Executive Summary

SongXY is a Chinese espionage APT that primarily uses spear‑phishing emails containing malicious RTF documents to exploit the CVE‑2018-0798 vulnerability in Microsoft Equation Editor and gain access to target systems. The group has targeted a broad spectrum of sectors—including government, defense, finance, media, energy, and healthcare—across multiple countries such as the US, EU states, India, Japan, and Russia. Operators collect system information and likely exfiltrate sensitive data through undisclosed channels.

Goals & Targeting

SongXY’s primary objective is strategic espionage, aiming to harvest confidential or proprietary information from entities deemed geopolitically or economically valuable. The group targets a wide array of industries—including defense, finance, media, energy, and healthcare—to support national intelligence objectives. Their global reach reflects both the need for diverse data sources and the potential to exploit high‑visibility victims whose reports may influence policy or market movements.

Enhanced Description

Key Capabilities

  • Spear‑phishing attachments delivering malicious RTF documents
  • Client‑side code execution via CVE‑2018‑0798 in Microsoft Equation Editor
  • Use of the Royal Road RTF builder for payload creation
  • System information discovery (OS, installed software, user accounts)
  • Capability to host payloads on attacker‑controlled HTTP/HTTPS servers

MITRE ATT&CK Tactics

Initial Access
Execution

ATT&CK Techniques

T1193 - Spearphishing Attachments
T1203 - Exploitation for Client Execution

Software / Tooling

RoyalRoad RTF Builder
Microsoft Equation Editor Exploit (CVE‑2018‑0798)

Campaigns & Victims

SongXY’s campaign pattern demonstrates a low‑profile, targeted approach that relies on socially engineered phishing campaigns rather than mass delivery. The group appears to deploy a one‑shot exploit chain: deliver an RTF file, trigger a client‐side vulnerability, then execute a small payload for reconnaissance. Victims are predominantly individuals or departments with access to sensitive data; there is no evidence of large‑scale lateral movement or persistence mechanisms beyond the initial foothold. Notable past operations include the documented incident where a document containing a link to an attacker‑controlled server was opened and automatically triggered exploitation. The lack of publicly known secondary malware, back‑doors, or advanced lateral propagation methods suggests SongXY operates with tight compartmentalization and may retain custom code that remains undisclosed.

IOC Patterns

  • Spear‑phishing email with malicious RTF attachment
  • Document triggers CVE‑2018‑0798 vulnerability in Equation Editor
  • Attacker‑controlled HTTPS server hosts payload
  • Use of Royal Road RTF builder for obfuscated document creation

Recommended Actions

  • Implement aggressive email filtering to block RTF attachments and suspicious file types; consider enforcing “attachment‑less” policy. Patch all Windows systems promptly to mitigate CVE‑2018‑0798 (Microsoft Equation Editor vulnerability). Deploy user education campaigns focused on phishing awareness, emphasizing caution with unexpected documents. Enable threat detection for the exploitation of Office/Word vulnerabilities via EDR solutions and endpoint monitoring. Implement network segmentation and least‑privilege principles to limit lateral movement if an initial compromise occurs.

Suggested Tags

APT
Chinese
Espionage
Cyberespionage
Spearphishing
Office Exploit
Equation Editor

Confidence Assessment

The assessment is based on a single publicly documented incident and limited contextual data. While the use of CVE‑2018‑0798 and RTF-based spear‑phishing is documented, many alias associations appear coincidental or derived from separate campaigns. Consequently, confidence in the attribution to SongXY as a cohesive APT is moderate; gaps exist regarding persistent capabilities, broader malicious toolset, and detailed operational tempo.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. pmc.ncbi.nlm.nih.gov — Cited by web research for: Sakaguchi S
  2. pmc.ncbi.nlm.nih.gov — Cited by web research for: CLEC5A-HER2
  3. misp-galaxy.org — Cited by web research for: cpyy

Intel Summary

2

Techniques

42

Tools

0

Campaigns

40

IOCs

0

Observed Data

1

Tactics

Tags

APT
Critical Infrastructure
Phishing
cyberespionage
China
Chinese
Espionage
Cyberespionage
Spearphishing
Office Exploit
Equation Editor

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.