Menu
Browse
Date:

Jun 2020

Location:

Viet Nam

Summary

A China-linked cyber-espionage group known as Cycldek conducted a sophisticated campaign targeting Vietnamese government and military entities, along with organizations in health, diplomacy, education, and political sectors. The attackers employed DLL side-loading techniques to deploy malicious payloads, including the FoundCore remote access Trojan, which enabled full system control, file manipulation, command execution, and screenshot capture. Additional malware like DropPhone and CoreLoader were used in the attacks, which established persistence, hid malicious processes, and connected to command-and-control infrastructure. Dozens of organizations were compromised, predominantly within Vietnam, with occasional targets in Central Asia and Thailand. The operation demonstrated increased technical evolution compared to the group's earlier activities.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

China-linked cyber-espionage group Cycldek, also known as Goblin Panda and Conimes, conducted a campaign targeting Vietnamese government and military entities between June 2020 and January 2021. The group, active since at least 2013, had historically focused on Southeast Asian governments but demonstrated increasing technical sophistication in this operation. Attackers employed an infection chain leveraging DLL side-loading to deliver malicious payloads, ultimately deploying the FoundCore remote access Trojan (RAT) on compromised systems. During an attack against a high-profile Vietnamese organization, threat actors abused a legitimate Microsoft Outlook component to load a malicious DLL. This DLL executed shellcode acting as a loader for FoundCore, which established persistence through multiple coordinated processes: one creating a service for persistence, another hiding that service, a third blocking access to malicious files, and a fourth connecting to command-and-control infrastructure.

Cyber Incident Image

The FoundCore RAT provided attackers with comprehensive control over infected machines, enabling file system manipulation, process execution, arbitrary command execution, and screenshot capture capabilities. Additional malware families including DropPhone and CoreLoader were deployed alongside FoundCore during the campaign. Kaspersky telemetry indicated dozens of affected organizations, with approximately 80% located in Vietnam across government, military, health, diplomatic, educational, and political sectors. Secondary targets included entities in Central Asia and Thailand. The incident represented a continuation of Cycldek's focus on Vietnamese targets following earlier campaigns, including a 2019 operation where the group deployed custom malware to breach air-gapped systems. No specific remediation actions or victim responses were detailed in available reporting.

Sources
Sources available to members
1 source