Also known as: Sakaguchi S, Akiba H, et al, CLEC5A-HER2, online supplemental figure S4, cpyy, APT3, Gothic Panda, UPS Team, TG-0110, DeputyDog, Parastoo, Newscaster, APT28, Pawn Storm, Fancy Bear, Sednit, MiniDionis, Hammertoss, Chinastrats, Patchwork
SongXY is believed to be an advanced persistent threat unit operating out of China that focuses on corporate espionage and state‑level intelligence gathering. Their typical attack chain begins with a spear‑phishing email that advertises or directly includes a malicious RTF file. When the victim opens this document, it exploits the Equation Editor flaw (CVE‑2018‑0798), allowing execution of arbitrary code under the user's privileges. The group leverages the Royal Road RTF builder tool to construct documents that embed the exploit payload seamlessly, exploiting the social engineering angle to increase click‑through rates. Once executed, the attacker can gather system configuration details—such as installed software, user accounts, and network settings—and potentially deploy additional backdoors or exfiltration agents. Although SongXY’s campaigns appear opportunistic in terms of sector, they tend to target assets containing strategic value like research data, defense secrets, financial records, and infrastructure control systems. The absence of large‑scale malware families in the public record suggests a more tailored and low‑profile approach compared to better‑known APTs such as APT28 or APT41. The threat actor’s catalog of aliases—ranging from Sakaguchi S and Akiba H to “Newscaster” and “Apt3”—often overlaps with other Chinese groups, which may obscure attribution efforts. Nevertheless, the consistent use of the Equation Editor exploit and spear‑phishing via RTF documents is a distinguishing signature. Finally, SongXY’s operational tempo appears moderate; incidents have surfaced sporadically over the past few years with no obvious coordinated multi‑phase campaigns detected so far.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
SongXY is a Chinese espionage APT that primarily uses spear‑phishing emails containing malicious RTF documents to exploit the CVE‑2018-0798 vulnerability in Microsoft Equation Editor and gain access to target systems. The group has targeted a broad spectrum of sectors—including government, defense, finance, media, energy, and healthcare—across multiple countries such as the US, EU states, India, Japan, and Russia. Operators collect system information and likely exfiltrate sensitive data through undisclosed channels.
Goals & Targeting
SongXY’s primary objective is strategic espionage, aiming to harvest confidential or proprietary information from entities deemed geopolitically or economically valuable. The group targets a wide array of industries—including defense, finance, media, energy, and healthcare—to support national intelligence objectives. Their global reach reflects both the need for diverse data sources and the potential to exploit high‑visibility victims whose reports may influence policy or market movements.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
SongXY’s campaign pattern demonstrates a low‑profile, targeted approach that relies on socially engineered phishing campaigns rather than mass delivery. The group appears to deploy a one‑shot exploit chain: deliver an RTF file, trigger a client‐side vulnerability, then execute a small payload for reconnaissance. Victims are predominantly individuals or departments with access to sensitive data; there is no evidence of large‑scale lateral movement or persistence mechanisms beyond the initial foothold. Notable past operations include the documented incident where a document containing a link to an attacker‑controlled server was opened and automatically triggered exploitation. The lack of publicly known secondary malware, back‑doors, or advanced lateral propagation methods suggests SongXY operates with tight compartmentalization and may retain custom code that remains undisclosed.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The assessment is based on a single publicly documented incident and limited contextual data. While the use of CVE‑2018‑0798 and RTF-based spear‑phishing is documented, many alias associations appear coincidental or derived from separate campaigns. Consequently, confidence in the attribution to SongXY as a cohesive APT is moderate; gaps exist regarding persistent capabilities, broader malicious toolset, and detailed operational tempo.
No campaigns linked yet.
No observed data linked yet.
2
Techniques
42
Tools
0
Campaigns
40
IOCs
0
Observed Data
1
Tactics