Rancor
MITRE ATT&CK: G0075 View on attack.mitre.org
Aliases: Rancor group, Rancor, Rancor Group, Rancor Taurus
- First seen
- 2017-12-01 00:00:00
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- Espionage
- Profile updated
- 2026-07-07 11:54:54
Targeted industries: government-and-public-sector media-and-entertainment
Targeted regions: country_code:id country_code:sg country_code:th country_code:my country_code:ph
Context
Rancor is a threat group that has led targeted campaigns against the South East Asia region. Rancor uses politically-motivated lures to entice victims to open malicious documents.
Detection coverage
- 4 YARA rules
- 248 Sigma rules
Malware & tools used
- Web Protocols (attack-pattern)
- Visual Basic (attack-pattern)
- Malicious File (attack-pattern)
- Scheduled Task (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Msiexec (attack-pattern)
- Windows Management Instrumentation Event Subscription (attack-pattern)
- Windows Command Shell (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- certutil (malware)
- PLAINTEE (malware)
- Reg (malware)
- DDKONG (malware)
Reports & references
- Palo Alto Unit 42 — Unit42 Rancor Targeted Attacks South East Asia Using Plaintee Ddkong Malware Families (report)
- cfr.org — Rancor (report)
- MITRE ATT&CK — G0075 (report)
- Palo Alto Unit 42 — Rancortaurus (report)
- researchcenter.paloaltonetworks.com — Unit42 Rancor Targeted Attacks South East Asia Using Plaintee Ddkong Malware Families (report)