Also known as: Hellsing, Goblin Panda, APT27, APT43, Emerald Sleet, APT 27, Cycledek, perhaps 1937CN
1937CN is a highly capable threat actor linked to Chinese cyber espionage efforts. Core delivery methods rely on macro‑enabled Microsoft Office documents that trigger rundll32 execution of shellcode via a custom loader called ShellFang, enabling initial compromise with limited user interaction. Once inside an environment, the actor leverages widely available public exploits (CVE‑2012‑0158 and CVE‑2017‑11882) to broaden footholds. Persistence is chiefly achieved through GPO manipulation: scheduled tasks are created on domain controllers, and legitimate system tools are hijacked via DLL side‑loading. This approach permits rapid lateral movement without raising obvious alerts in typical monitoring setups. Additionally, advanced adversary techniques such as PowerShell downgrade attacks evade script‑block logging, while RC4‑encrypted payloads obscure data exfiltration. For command and control, the group uses web protocols (HTTPS and HTTP) alongside internal and external proxies to tunnel traffic. Communication is sometimes embedded in seemingly legitimate Office macro traffic or routed through compromised domain names shared with broader Chinese state actors. Remote access trojans—including PlugX/Korplug, NewCore RAT, Sisfader, and MACAMAX—provide persistent footholds, allowing credential harvesting, file manipulation, screen capture, and privileged command execution. Known campaigns include the 2016 disruption of Vietnamese commercial flights via airport control systems, evidence of which indicates that 1937CN’s scope extends beyond espionage into sabotage. Recent operations target Southeast Asian firms across telecom, technology, and media sectors, often utilizing GPO‑based spread to gain domain‑level persistence. The actor’s tactics reveal a layered approach: initial macro delivery, exploitation of known CVEs, lateral movement via GPO/SharpHound, obfuscation through DLL side‑loading and header stripping, and exfiltration using cloud storage or encrypted archives.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
1937CN—also known as Goblin Panda or APT27—is a Chinese state‑sponsored APT that uses macro‑enabled Office documents and other public vulnerabilities to deliver malicious payloads, spread through Group Policy Objects (GPO), and exfiltrate data from critical infrastructure and government entities. Their operations combine sophisticated persistence via GPO‑based scheduled tasks with remote access trojans such as PlugX and NewCore RAT, while employing anti‑analysis techniques like DLL sideloading and PowerShell downgrade attacks. The group has repeatedly targeted aviation, telecom, media, and food‑agriculture sectors across China, Vietnam, the Netherlands, Taiwan, India, and the United States.
Goals & Targeting
1937CN appears driven primarily by state espionage objectives—gathering intelligence on governmental agencies, critical infrastructure, and commercial entities in the Asia‑Pacific region. Their focus on aviation, telecommunications, defense, and food‑agriculture indicates an intent to map out strategic sectors that could influence national security or economic interests. By employing low‑interaction initial access vectors (macros) and persistent GPO‐based tactics, they minimize detection while maintaining a broad operational footprint across multiple countries.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
1937CN’s documented activity spans from attacks on Vietnamese aviation infrastructure—such as the 2016 airport disruption—to broader campaigns targeting Southeast Asian telecom, technology, and media firms since 2020. The group frequently employs GPO-based lateral movement and persistence, leveraging domain-wide templates to install malicious payloads efficiently. Operational tempo appears moderate, with coordinated bursts of activity that coincide with high‑value diplomatic or economic events involving target nations. Notably, the actor demonstrates an evolving toolset including both legacy Cobalt Strike beacons and custom Go‑Lang backdoors, suggesting continuous development of tailored capabilities.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available data provides a solid foundation for identifying 1937CN’s TTPs, tools, and target focus; however, some ambiguity remains regarding the precise operational scope (e.g., the balance between espionage and sabotage) and the extent of internal coordination with other Chinese actors. Attribution confidence is moderate to high based on consistent macro‑based delivery, GPO persistence, and shared toolsets across reported incidents, but verification through additional corroborative indicators would strengthen certainty.
No campaigns linked yet.
No observed data linked yet.
44
Techniques
55
Tools
0
Campaigns
41
IOCs
0
Observed Data
11
Tactics