Cycldek
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Cycldek, also known as Goblin Panda and Conimes, is a China-linked cyber‑espionage group that has been active since at least 2013. The group focuses its operations on governments and related entities in Southeast Asia, with a particular emphasis on Vietnamese targets, while also occasionally targeting organizations in the health, diplomacy, education and political sectors as well as occasional victims in Central Asia and Thailand. Its activities are described in open‑source reporting as cyber‑espionage, with a demonstrated interest in gathering intelligence from governmental and military networks. The group’s location is identified as China in the provided context, and it is referenced alongside its alternative aliases in multiple sources.
Cycldek’s tactics include the use of DLL side‑loading to deliver malicious code, a technique observed in a campaign that abused a legitimate Microsoft Outlook component to load a DLL that executed a shellcode loader for the FoundCore remote access Trojan. Once deployed, FoundCore establishes persistence as a service, hides its primary process, blocks access to the malicious file and establishes a command‑and‑control channel, providing the attacker with full control over the victim’s system, including file system manipulation, process manipulation, arbitrary command execution and screenshot capture. In addition to FoundCore, the group has delivered the DropPhone and CoreLoader malware families during its operations. Earlier reporting noted that the group had employed a custom malware tool to exfiltrate data from air‑gapped systems, indicating an evolution in its capabilities.
One of the group’s more recent campaigns ran from June 2020 to January 2021 and relied on the DLL side‑loading chain described above to compromise dozens of organizations, with approximately eighty percent of the victims located in Vietnam and belonging to the government, military, health, diplomacy, education or political verticals; occasional targets were also identified in Central Asia and Thailand. Prior to this campaign, the group was noted for using a custom malware specimen to steal data from air‑gapped systems, a development that marked a increase in sophistication for a group previously considered less advanced. These operations illustrate Cycldek’s focus on gaining persistent access to sensitive networks and extracting valuable information.
Attribution to Cycldek is based on its description as a China‑linked cyber‑espionage group and its association with the aliases Goblin Panda and Conimes in the source material. The group’s infrastructure and tooling have been linked to China in public reporting, although the sources stop short of assigning a specific state sponsor. The profile presented here is limited to the facts explicitly provided in the supplied articles, without extrapolation beyond those details.
Incidents
Attributed incidents are available to members.
0 incidents