Home/Threat Actor/Goblin Panda
Threat Actor

Goblin Panda

goblin_panda_1937cn · china · active since 2013

Goblin Panda (1937CN / Conimes / Cycldek / G0078) is a suspected China-aligned MSS-tasking cyber-espionage cluster active since at least 2013, one of the longest-running publicly-tracked China-aligned clusters focused on Southeast Asian victim categories, with fragmented vendor naming across CrowdStrike's Goblin Panda, FireEye's 1937CN, Kaspersky's Conimes and Cycldek streams (modern vendor consensus treats the four as alternative names for the same operational cluster), responsible for sustained operations against Vietnamese ministries of foreign affairs, Communist Party of Vietnam organs, military and defense industrial targets, state-owned oil-and-gas companies (PetroVietnam), Vietnamese academic institutions, and broader Southeast Asian regional government targets, defined operationally by sustained Vietnamese targeting aligned with PRC strategic interest in China-Vietnam bilateral relations and South China Sea disputes, by the signature NewCore RAT + Sisfader + Conimes downloader + Cycldek backdoor toolkit, by the distinctive USBFerry and USBCulprit removable-media-worm air-gap-traversal tradecraft documented in Kaspersky's June 2020 "Cycldek: Bridging the (air) gap" seminal disclosure (parallel to similar regional tradecraft patterns in already-covered Naikon and Aoqin Dragon), and by operational tempo alignment with South China Sea political and arbitration events including the July 2016 Permanent Court of Arbitration ruling and subsequent ASEAN summits with South China Sea agenda items.

china confidence: medium 18 aliases

Profile

Goblin Panda (also tracked as 1937CN, Conimes, Cycldek, and MITRE ATT&CK G0078) is a suspected China-aligned cyber-espionage cluster active since at least 2013 and one of the longest-running publicly- tracked China-aligned clusters focused on Southeast Asian victim categories. The cluster's vendor-naming taxonomy is fragmented: "Goblin Panda" is the CrowdStrike-canonical name.

"1937CN" was introduced by FireEye / Mandiant based on operational artifacts and infrastructure indicators tied to 1937CN-themed domains (the name reflects the historical context of the Marco Polo Bridge Incident of July 7, 1937, the start of the Second Sino- Japanese War, and has been speculatively linked to operator- identity political alignment)

"Conimes" is the Kaspersky naming derived from the Conimes downloader implant.

and "Cycldek" is Kaspersky's evolved tracking naming. Modern vendor consensus treats the four naming streams as alternative names for the same operational cluster with substantial victimology and toolkit overlap, though the consolidation question remains analytically open. The cluster is widely assessed to operate in alignment with Chinese state intelligence interests, most commonly framed as MSS (Ministry of State Security) tasking.

the specific MSS bureau has not been formally established. No formal government attribution event has been issued. The cluster's most defining victim signature is sustained Vietnamese government and defense targeting across more than a decade. Continuous operations against Vietnamese ministries of foreign affairs, Communist Party of Vietnam organs, military and defense industrial targets, state-owned oil-and-gas companies (notably PetroVietnam entities), and Vietnamese academic institutions. The Vietnamese focus aligns with sustained PRC strategic interest in Vietnamese government posture toward China-Vietnam bilateral relations and South China Sea disputes , the latter being one of the most consequential ongoing Asia- Pacific maritime territorial disputes. The cluster's sustained Vietnamese targeting represents one of the most operationally consistent single-country focuses among publicly-tracked China- aligned clusters and parallels the Tick / Bronze Butler Japanese focus and the Sea Turtle Turkish-MIT-suspected focus already covered in this corpus. A defining cluster tradecraft signature is sustained use of USBFerry and USBCulprit removable-media-worm components for air-gap traversal and lateral movement in target environments. Kaspersky's June 2020 "Cycldek: Bridging the (air) gap" disclosure documented the tradecraft in detail. The USB-worm capability exploits the USB-media-sharing workflow prevalent in Southeast Asian government environments where air-gapped or partially-isolated networks remain operationally common. The tradecraft is conceptually similar to the removable-media patterns of APT30 / Naikon (already consolidated under naikon.yaml) and Aoqin Dragon (already covered as aoqin_dragon.yaml), making air-gap-traversal-via-removable-media a meaningful regional tradecraft pattern across at least three publicly-tracked China-aligned clusters operating against Southeast Asian targets. Operationally the cluster's toolkit centers on signature implants NewCore RAT (the cluster's central modern Windows backdoor), Sisfader (sibling Windows backdoor), the Conimes downloader (a lightweight initial-stage implant that gave the cluster one of its canonical vendor names), and the Cycldek backdoor. Beyond these signature implants the cluster operates PlugX (a commodity RAT shared across multiple PRC-aligned clusters, PlugX-presence- alone insufficient for cluster attribution), SPLM, USBFerry, USBCulprit, China Chopper webshells, Cobalt Strike Beacon, PoisonIvy, and Mimikatz. The toolkit pattern is moderately diverse for a single-country-focused regional cluster, reflecting sustained capability development across the operational lifespan. Initial-access tradecraft is predominantly spear-phishing with weaponized Office documents (CVE-2012-0158, CVE-2014-1761, CVE-2014-6332, CVE-2017-0199, CVE-2017-11882, CVE-2018-0798, CVE-2018-0802, CVE-2022-30190 Follina) using Vietnamese-language and regional-government-themed lures. The cluster has not demonstrated 0day-development capability and primarily relies on rapid weaponization of disclosed n-day vulnerabilities. A defining operational pattern is sustained tempo alignment with South China Sea political and arbitration events. Notable elevated cluster activity has been documented surrounding the July 2016 Permanent Court of Arbitration ruling in the Philippines vs China case (which rejected China's "nine-dash line" claims), subsequent ASEAN summits with South China Sea agenda items, and bilateral negotiations between China and Southeast Asian claimant states. The summit-and-arbitration- event-anchored targeting pattern is one of the most analytically interesting operational patterns observable in publicly-tracked China-aligned clusters targeting Southeast Asia. A handful of operational notes: First, the cluster's vendor-naming proliferation (Goblin Panda / 1937CN / Conimes / Cycldek) reflects fragmented vendor tracking across multiple years and reporting streams. Modern reporting should default to "Goblin Panda" as the CrowdStrike-canonical name and the MITRE-tracked identifier (G0078). The four primary aliases should be treated as alternative names for the same operational cluster pending any formal disambiguation. Second, the cluster is operationally distinct from Naikon (already covered as naikon.yaml, PLA Unit 78020, broader Southeast Asia and Pacific focus, APT30 consolidated), from Aoqin Dragon (already covered as aoqin_dragon.yaml, decade pre-disclosure, SE Asia/Australia, Mongall+Heyoka USB-worm), and from APT40 / Leviathan (already covered as apt40_leviathan.yaml , maritime/shipping focus, Hainan State Security Department attribution). All four clusters operate against Southeast Asian targets but represent separable operational identities based on toolkit, victim emphasis, and tradecraft. Third, attribution to MSS specifically, though dominant in vendor reporting, has not been confirmed by formal government attribution. Treat the MSS-tasking framing as suspected at the bureau level even though the broader China-aligned framing is vendor-research-consensus high-confidence. Fourth, Vietnamese cybersecurity firm VinCSS has published sustained Vietnamese-language tracking of the cluster's operations , a useful operational data source for defender or researcher work in the Southeast Asian victim space that complements the English-language international-vendor reporting.

Aliases

18
goblin pandagoblin_pandagoblinpanda1937cn1937 cn1937_cnconimescycldekcy cldekcy_cldekhellsing relatedhellsing_relatedlotus blossom adjacentlotus_blossom_adjacentapt27 adjacentg0078atk 32atk32

Notable Campaigns

9
2022-2025Continued Operations (2022-2025)
2020Bitdefender: 1937CN / Cycldek Overlap Investigation (June 2020)
2018-2024USBFerry / USBCulprit Removable-Media Air-Gap-Traversal Tradecraft (2018-2024)
2018-2024Vietnamese News Media and Journalist Targeting (2018-2024)
2018-2020Kaspersky: Conimes / Cycldek Disclosures (2018-2020)
2016-2024South China Sea Political Event Targeting (2016-2024)
2014-2024Sustained Vietnamese Government and Defense Targeting (2014-2024)
2014-2015CrowdStrike: Goblin Panda Naming (2014-2015)
2014FireEye / Mandiant: 1937CN Attribution (2014 onward)

Attribution & Reporting

Attributed by
CrowdStrikeKaspersky GReATMandiant / FireEyeTrend MicroESETBitdefenderSentinelOneCisco TalosMicrosoftRecorded Future Insikt GroupVinCSS (Vietnamese cybersecurity firm)Group-IBCluster25Cyfirma360 Threat Intelligence CenterQiAnXin Threat Intelligence CenterPWC Threat Intelligence
Key reporting
reportCrowdStrike: Goblin Panda Targets Vietnam, Sustained Tracking (2014-2024)
reportFireEye / Mandiant: 1937CN Adversary Profile (2014 onward)
reportKaspersky GReAT: Asia-Targeted Cycldek / Conimes Malware (June 2018)
reportKaspersky GReAT: Cycldek, Bridging the (Air) Gap (June 2020), seminal USB-worm tradecraft disclosure
reportESET: Cycldek Bridging Air Gap Conimes (June 2019)
reportBitdefender: Cycldek Whitepaper (June 2020), 1937CN/Cycldek overlap investigation
reportTrend Micro: USBFerry Recent Activities (2020), adjacent USB-worm context
reportVinCSS (Vietnamese cybersecurity firm): Goblin Panda Vietnamese-language Tracking (multiple years)
reportQiAnXin Threat Intelligence Center: 1937CN / Goblin Panda Tracking (Chinese-language)
report360 Threat Intelligence Center: APT Tracking (Chinese-language)
reportRecorded Future Insikt Group: Goblin Panda China-Vietnam Tracking (multiple years)
reportSekoia: Goblin Panda 1937CN Cycldek Tracking (2023-2024)
reportCyfirma: Goblin Panda APT Tracking (multiple years)
reportCluster25: Goblin Panda Operational Profile (2022-2024)
reportMalpedia Actor Profile: Goblin Panda
reportMITRE ATT&CK Group G0078, Goblin Panda

Operational

State sponsor

Suspected China-aligned cyber-espionage cluster, widely assessed by vendor research (CrowdStrike 2014 Goblin Panda introduction, Kaspersky 2014 onward Cycldek and Conimes tracking, FireEye / Mandiant 2014 1937CN naming, Trend Micro tracking, ESET 2018+, Bitdefender 2020, others) to operate in alignment with Chinese state intelligence interests, most commonly framed as MSS (Ministry of State Security) tasking with operational alignment to PRC strategic interest in Southeast Asian regional collection, particularly Vietnamese government and military targets relevant to South China Sea disputes and Sino-Vietnamese bilateral relations. The specific MSS bureau has not been formally established. The cluster name is fragmented across multiple vendor-naming streams: "Goblin Panda" (CrowdStrike), "1937CN" (FireEye and some Chinese vendors), "Conimes" (Kaspersky, derived from the Conimes downloader implant), and "Cycldek" (Kaspersky later tracking).

Whether the four naming streams represent the same operational cluster, closely-overlapping sibling clusters within the same PRC ecosystem, or distinct clusters with shared tooling has been analytically open across vendor reporting. Modern vendor consensus tends toward treating Goblin Panda, 1937CN, Conimes, and Cycldek as alternative names for the same operational cluster with substantial victimology and toolkit overlap. No formal US, UK, EU, Vietnamese, or other government attribution event has been issued.

The cluster has been active since at least 2013 and represents one of the longest-running publicly-tracked China-aligned clusters focused on Southeast Asian victim categories.

Motivations
espionage, intelligence_gathering, geopolitical_collection, south_china_sea_collection, regional_intelligence, mekong_delta_political_collection, economic_espionage, economic_intelligence
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)56/60 · 93%
Analytics (MITRE CAR)26/60 · 43%
Runtime / container (Falco)6/60 · 10%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)14/60 · 23%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

3 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MSHTASIS FADERSISFADERSPLM RAT
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin