Cycldek — APT Profile
Cycldek is a Chinese-speaking cyber espionage group active since at least 2013, tracked by Kaspersky and CrowdStrike and best known for sustained operations against government and diplomatic targets in Southeast Asia, with Vietnam as its most consistently documented victim. Its campaigns pair spear-phishing that weaponises long-patched Microsoft Office flaws with DLL sideloading to deploy the BlueCore and RedCore backdoors, two related implant families whose deployment splits along geographic lines. The group also developed USBCulprit, a tool built to exfiltrate data from air-gapped machines by staging it on removable drives.Also tracked as
Goblin Panda, Conimes
Vendor research
- The leap of a Cycldek-related threat actor Kaspersky (GReAT)
- Meet CrowdStrike's Adversary of the Month for August: GOBLIN PANDA CrowdStrike
- Cycldek: Bridging the (air) gap Kaspersky (GReAT)
Countries linked to this actor
- Vietnam targets