Rancor

🔴 High
Also known as: G0075, Rancor, RANCOR, Rancor group, Rancor Group, Rancor Taurus

Rancor is a threat group that has led targeted campaigns against the South East Asia region. Rancor uses politically-motivated lures to entice victims to open malicious documents. Rancor Unit42 June 2018

🌍 Country China
Risk Level High
🎯 Incident Type Espionage
🧭 ATT&CK G0075
Government Civil society

Introduction

Rancor is a threat group that has led targeted campaigns against the South East Asia region. Rancor uses politically-motivated lures to entice victims to open malicious documents. Rancor Unit42 June 2018

Activities and Tactics

Targeted Sectors: Government, Civil society

Country of Origin: 🇨🇳 China

Risk Level: High

Incident Type: Espionage

Suspected Victims: Singapore, Cambodia

Notable Campaigns

Information pending cataloguing.

Tactics, Techniques, and Procedures (TTPs)

ATT&CK technique IDs (denormalized)

Notable Indicators of Compromise (IOCs)

No curated IOCs are currently published for this actor. This section will be updated when stable, attributable indicators are available.

Malware and Tools

  • KHRAT Trojan:
  • Derusbi:
  • Dudell:
  • DDKONG Plugin:

MITRE ATT&CK Software

Attribution and Evidence

Country of Origin: China Additional attribution information pending cataloguing.

References

[1] mitre-attack [3] Rancor Unit42 June 2018 Ash, B., et al. (2018, June 26). RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families. Retrieved July 2, 2018.