Threat group.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1053.005 Scheduled Task |
Rancor launched a scheduled task to gain persistence using the |
| T1059.003 Windows Command Shell |
Rancor has used cmd.exe to execute commmands. |
| T1059.005 Visual Basic |
Rancor has used VBS scripts as well as embedded macros for execution. |
| T1071.001 Web Protocols |
Rancor has used HTTP for C2. |
| T1105 Ingress Tool Transfer |
Rancor has downloaded additional malware, including by using certutil. |
| T1204.002 Malicious File |
Rancor attempted to get users to click on an embedded macro within a Microsoft Office Excel document to launch their malware. |
| T1218.007 Msiexec |
Rancor has used |
| T1546.003 Windows Management Instrumentation Event Subscription |
Rancor has complied VBScript-generated MOF files into WMI event subscriptions for persistence. |
| T1566.001 Spearphishing Attachment |
Rancor has attached a malicious document to an email to gain initial access. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.