Rancor

G0075

Threat group.View on attack.mitre.org

About this group

Rancor is a threat group that has led targeted campaigns against the South East Asia region. Rancor uses politically-motivated lures to entice victims to open malicious documents.

Techniques used9

Procedure examples9

TechniqueProcedure example
T1053.005
Scheduled Task

Rancor launched a scheduled task to gain persistence using the schtasks /create /sc command.

T1059.003
Windows Command Shell

Rancor has used cmd.exe to execute commmands.

T1059.005
Visual Basic

Rancor has used VBS scripts as well as embedded macros for execution.

T1071.001
Web Protocols

Rancor has used HTTP for C2.

T1105
Ingress Tool Transfer

Rancor has downloaded additional malware, including by using certutil.

T1204.002
Malicious File

Rancor attempted to get users to click on an embedded macro within a Microsoft Office Excel document to launch their malware.

T1218.007
Msiexec

Rancor has used msiexec to download and execute malicious installer files over HTTP.

T1546.003
Windows Management Instrumentation Event Subscription

Rancor has complied VBScript-generated MOF files into WMI event subscriptions for persistence.

T1566.001
Spearphishing Attachment

Rancor has attached a malicious document to an email to gain initial access.

Software4

Campaigns0

None recorded.

References1

  1. Rancor Unit42 June 2018 Open source
    Ash, B., et al. (2018, June 26). RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families. Retrieved July 2, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.