Loader
8.t Dropper
aka 8t_dropper · RoyalRoad
8T_Dropper has been used by Chinese threat actor TA428 in order to install Cotx RAT onto victim's machines during Operation LagTime IT.
8.t Dropper, also known as 8t_dropper, RoyalRoad, is a Windows loader operated by Hellsing, Ice Fog and others.
Background
During Operation LagTime IT, the Chinese threat actor TA428 relied on 8T_Dropper to deploy Cotx RAT onto compromised hosts. Proofpoint reported that the campaign was aimed at several East Asian government bodies responsible for areas such as government IT, domestic and foreign affairs, economic development, and political processes. The dropper itself was delivered inside an RTF document that exploited CVE-2018-0798.
Source: Malpedia (Fraunhofer FKIE).