Rancor

MITRE ATT&CK: G0075 View on attack.mitre.org

Aliases: Rancor group, Rancor, Rancor Group, Rancor Taurus

First seen
2017-12-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
Espionage
Profile updated
2026-07-07 11:54:54

Targeted industries: government-and-public-sector media-and-entertainment

Targeted regions: country_code:id country_code:sg country_code:th country_code:my country_code:ph

Context

Rancor is a threat group that has led targeted campaigns against the South East Asia region. Rancor uses politically-motivated lures to entice victims to open malicious documents.

Detection coverage

  • 4 YARA rules
  • 248 Sigma rules

Malware & tools used

  • Web Protocols (attack-pattern)
  • Visual Basic (attack-pattern)
  • Malicious File (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Msiexec (attack-pattern)
  • Windows Management Instrumentation Event Subscription (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • certutil (malware)
  • PLAINTEE (malware)
  • Reg (malware)
  • DDKONG (malware)

Reports & references

  • Palo Alto Unit 42 — Unit42 Rancor Targeted Attacks South East Asia Using Plaintee Ddkong Malware Families (report)
  • cfr.org — Rancor (report)
  • MITRE ATT&CK — G0075 (report)
  • Palo Alto Unit 42 — Rancortaurus (report)
  • researchcenter.paloaltonetworks.com — Unit42 Rancor Targeted Attacks South East Asia Using Plaintee Ddkong Malware Families (report)

External references