Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors 1937CN

Also known as: Hellsing, Goblin Panda, APT27, APT43, Emerald Sleet, APT 27, Cycledek, perhaps 1937CN

Description

1937CN is a highly capable threat actor linked to Chinese cyber espionage efforts. Core delivery methods rely on macro‑enabled Microsoft Office documents that trigger rundll32 execution of shellcode via a custom loader called ShellFang, enabling initial compromise with limited user interaction. Once inside an environment, the actor leverages widely available public exploits (CVE‑2012‑0158 and CVE‑2017‑11882) to broaden footholds. Persistence is chiefly achieved through GPO manipulation: scheduled tasks are created on domain controllers, and legitimate system tools are hijacked via DLL side‑loading. This approach permits rapid lateral movement without raising obvious alerts in typical monitoring setups. Additionally, advanced adversary techniques such as PowerShell downgrade attacks evade script‑block logging, while RC4‑encrypted payloads obscure data exfiltration. For command and control, the group uses web protocols (HTTPS and HTTP) alongside internal and external proxies to tunnel traffic. Communication is sometimes embedded in seemingly legitimate Office macro traffic or routed through compromised domain names shared with broader Chinese state actors. Remote access trojans—including PlugX/Korplug, NewCore RAT, Sisfader, and MACAMAX—provide persistent footholds, allowing credential harvesting, file manipulation, screen capture, and privileged command execution. Known campaigns include the 2016 disruption of Vietnamese commercial flights via airport control systems, evidence of which indicates that 1937CN’s scope extends beyond espionage into sabotage. Recent operations target Southeast Asian firms across telecom, technology, and media sectors, often utilizing GPO‑based spread to gain domain‑level persistence. The actor’s tactics reveal a layered approach: initial macro delivery, exploitation of known CVEs, lateral movement via GPO/SharpHound, obfuscation through DLL side‑loading and header stripping, and exfiltration using cloud storage or encrypted archives.

Goals & Targeting

Targeted Sectors

Government
Aviation
Telecommunications
Defense
Media
Food agriculture
Critical infrastructure

Targeted Countries / Regions

CN
VN
NL
TW
IN
US

AI Analysis

Grounded in web research
· analyzed in 5 chunks · 3 days ago

Executive Summary

1937CN—also known as Goblin Panda or APT27—is a Chinese state‑sponsored APT that uses macro‑enabled Office documents and other public vulnerabilities to deliver malicious payloads, spread through Group Policy Objects (GPO), and exfiltrate data from critical infrastructure and government entities. Their operations combine sophisticated persistence via GPO‑based scheduled tasks with remote access trojans such as PlugX and NewCore RAT, while employing anti‑analysis techniques like DLL sideloading and PowerShell downgrade attacks. The group has repeatedly targeted aviation, telecom, media, and food‑agriculture sectors across China, Vietnam, the Netherlands, Taiwan, India, and the United States.

Goals & Targeting

1937CN appears driven primarily by state espionage objectives—gathering intelligence on governmental agencies, critical infrastructure, and commercial entities in the Asia‑Pacific region. Their focus on aviation, telecommunications, defense, and food‑agriculture indicates an intent to map out strategic sectors that could influence national security or economic interests. By employing low‑interaction initial access vectors (macros) and persistent GPO‐based tactics, they minimize detection while maintaining a broad operational footprint across multiple countries.

Enhanced Description

Key Capabilities

  • Macro-enabled Office document delivery
  • Rundll32 shellcode execution
  • Custom ShellFang loader
  • Domain enumeration via SharpHound
  • GPO-based malware distribution and persistence
  • DLL side‑loading/hijacking
  • Exploitation of public CVEs (CVE-2012-0158, CVE-2017-11882)
  • Use of remote access trojans (PlugX/Korplug, NewCore RAT, Sisfader)
  • PowerShell downgrade attack
  • File and directory manipulation (copy, delete, rename, search)
  • Screen capture/monitoring
  • Process injection
  • Timestomping
  • Deobfuscation/decoding
  • Indicator removal
  • Domain trust discovery
  • Account discovery
  • Scheduled task creation
  • Group Policy modification
  • Internal/external proxy usage
  • Web protocol C2 communication

MITRE ATT&CK Tactics

Persistence
Execution
Defense Evasion
Discovery
Command and Control
Exfiltration
Privilege Escalation

ATT&CK Techniques

T1027
T1041
T1042
T1046
T1048
T1060
T1069.001
T1070
T1070.004
T1070.006
T1071.001
T1071.004
T1074
T1078
T1083
T1086
T1087
T1090.001
T1090.002
T1090.003
T1105
T1107
T1113
T1117
T1140
T1204.002
T1482
T1484
T1484.001
T1547.009
T1562.010
T1566.001
T1573.002
T1574.002
T1574.003
T1053
T1053.005
T1053.001
T1055
T1119
T1489
T1520

Software / Tooling

Cobalt Strike
SharpHound
ShellFang
PlugX
Korplug
NewCore RAT
Sisfader
MACAMAX backdoor
EarthWorm
WinRAR
PowerShell
Rundll32

Campaigns & Victims

1937CN’s documented activity spans from attacks on Vietnamese aviation infrastructure—such as the 2016 airport disruption—to broader campaigns targeting Southeast Asian telecom, technology, and media firms since 2020. The group frequently employs GPO-based lateral movement and persistence, leveraging domain-wide templates to install malicious payloads efficiently. Operational tempo appears moderate, with coordinated bursts of activity that coincide with high‑value diplomatic or economic events involving target nations. Notably, the actor demonstrates an evolving toolset including both legacy Cobalt Strike beacons and custom Go‑Lang backdoors, suggesting continuous development of tailored capabilities.

IOC Patterns

  • Macro-enabled Office document with embedded VBA that invokes rundll32.exe
  • Shellcode loader leveraging Cobalt Strike shellcode via ShellFang
  • GPO-based malware distribution and persistence
  • Domain enumeration via SharpHound
  • DLL side-loading/hijacking patterns
  • Legacy PowerShell execution (downgrade attack)
  • Header deletion/wiping in shellcode loaders
  • SHA-256 hash signatures of malware samples
  • RC4 encrypted payloads
  • Password-protected WinRAR archives for data exfiltration
  • Dynamic API resolution and hashing by Windows APIs
  • Exception-based obfuscation flow
  • Scheduled task creation for persistence
  • Process injection activities
  • Timestamp manipulation (timestomping)
  • Internal/external proxy usage
  • Domain trust discovery activity

Recommended Actions

  • Disable or strictly whitelist Office macros
  • Patch systems for CVE‑2012-0158 and CVE‑2017-11882 and monitor impacted endpoints
  • Audit and restrict Group Policy Object modifications to prevent GPO-based spread and persistence
  • Deploy EDR that detects rundll32 execution and shellcode injection
  • Block or closely monitor Cobalt Strike traffic and beacon signatures
  • Detect and block DLL side-loading/hijacking, including renaming of legitimate executables
  • Monitor for PowerShell downgrade attacks by enforcing latest versions and enabling Script Block Logging
  • Implement antivirus/EDR rules for known RAT behaviors (PlugX/Korplug, NewCore RAT, Sisfader) and shellcode loaders like ShellFang
  • Enforce least privilege on domain controllers and harden authentication controls
  • Monitor scheduled task creation and abnormal RunKey registry modifications to identify persistence attempts
  • Detect timestamp manipulation, header deletion in loader files, and other anti‑analysis techniques
  • Track domain and account discovery activity using tools like SharpHound; block unauthorized enumeration scans
  • Monitor proxy usage (internal/external) and restrict outbound data transfers to services such as Dropbox or cloud storage
  • Detect password-protected WinRAR/ZIP archives and RC4-encrypted payloads, quarantine them if from unknown domains
  • Enable logging of dynamic API resolution events for anomaly detection

Suggested Tags

Chinese state-sponsored actor
1937CN
Goblin Panda
APT27
Earth Zhulong
macro delivery
GPO lateral movement
DLL side-loading
Office macro delivery
CVE exploitation
PowerShell downgrade attack
Remote Access Trojans
PlugX
NewCore RAT
Sisfader
MACAMAX backdoor
Domain trust discovery
Account discovery
Scheduled task persistence
Timestomping
Exfiltration via Dropbox
RC4 encryption
Airline and aviation targeting
South‑East‑Asia targeting

Confidence Assessment

The available data provides a solid foundation for identifying 1937CN’s TTPs, tools, and target focus; however, some ambiguity remains regarding the precise operational scope (e.g., the balance between espionage and sabotage) and the extent of internal coordination with other Chinese actors. Attribution confidence is moderate to high based on consistent macro‑based delivery, GPO persistence, and shared toolsets across reported incidents, but verification through additional corroborative indicators would strengthen certainty.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

SHA-256 Hash 20
SHA-256 Hash 20
8485d9ecfa94f3cd316057c97e13629973b7e110bdee288087f98338b67d8b48
50% TLP:CLEAR
dacb62e6a86a4ecd4f8f5e1685de018258b36372bad5d58bc9745725e2d04f8f
50% TLP:CLEAR
78ce3dcbe9b828b9be0c1a74757eb8f32052db171cde2f2e2fe897a8096f1140
50% TLP:CLEAR
8023c060d49479466b6595c72f07d89a6e598b8bde6805cdffcc52d1169d0304
50% TLP:CLEAR
c9b96665e6962ccb47fb9963c3db6b0d9aebaedf717c42ac6ba321d7981dd69e
50% TLP:CLEAR
e7def95e889704343557431aa30914faafeb5318bb2f0f6e7a00c6b319a5edd7
50% TLP:CLEAR
b88cd263828b9856c1cee7eeecdd6da22eb9c892cbbd38c5bdab284f2a007582
50% TLP:CLEAR
5e488198c47befc49a08fec6f19c3c7d8e0e955589465d4e83ba87b46b3d80df
50% TLP:CLEAR
22b0f774379c0e28211ffb53722d8cd5727da8e02aada3507be81d888864770f
30% TLP:CLEAR
471c075d5e3c9cb009fa6ef1f8ec9c0ecf61251b4dab6eea161abec6935272bf
50% TLP:CLEAR
32946f137deb4d2abb7c71c021984e0d5364b6ee80560e09de133d8c11a5cf72
50% TLP:CLEAR
c1b9d0639d416232995d5eef2515c9d9be0f694e67b1136d7c5d37ca2af2dacd
30% TLP:CLEAR
c299841e17b621db7a386c24f426a0a74912758b19ecfc368fabc8fb4742ab9c
50% TLP:CLEAR
c9fb110ec68fd7fde1b72c5d92be5f6f03559d11a5d863e2179ebecc8fce2aee
50% TLP:CLEAR
c8f19e0f7bbb63919df67f93d3c334e9564bf3aea910951d9ba644ae30783439
50% TLP:CLEAR
5cef63d737153624211a6c408ef6b9ae008837f54f0ba44cbaefa57d8fde34f8
50% TLP:CLEAR
a270058cef51b49905d7ceb3df7b8b5bb7b60ebfb5099d8b177dc19a2064145c
50% TLP:CLEAR
f910c0b18b5af4359e7354475add9f622aa92f945739a1c3b3bfc3704a037561
50% TLP:CLEAR
fce7a763c05711bc0ba110ed23651c0f18aceddae5ada6e8042a2664a35d18ec
50% TLP:CLEAR
e5a170755ab090e944d1d24faef67ae1f80bac847f2a501937c9f03b888615c8
50% TLP:CLEAR

References

Intel Summary

44

Techniques

55

Tools

0

Campaigns

41

IOCs

0

Observed Data

11

Tactics

Tags

Government Targeting
Hacktivism
APT
Cyber espionage
Geopolitical
Southeast Asia
SoutheastAsia
VietnamAirlines
EmbassyTarget
ChinaStateActor
APT27
Kimsuky
1937CN
EarthZhulong
dll-side-loading
powerhell-downgrade
gpo-persistence
cobalt-Strike
newcore-rat
shellfang-loader
themida-obfuscation
EmeraldSleet
SharpHound
Chinese state-sponsored actor
Goblin Panda
Earth Zhulong
macro delivery
GPO lateral movement
DLL side-loading
Office macro delivery
CVE exploitation
PowerShell downgrade attack
Remote Access Trojans
PlugX
NewCore RAT
Sisfader
MACAMAX backdoor
Domain trust discovery
Account discovery
Scheduled task persistence
Timestomping
Exfiltration via Dropbox
RC4 encryption
Airline and aviation targeting
South‑East‑Asia targeting

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.