ATT&CKReferencesRancor Unit42 June 2018

Rancor Unit42 June 2018

Ash, B., et al. (2018, June 26). RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families. Retrieved July 2, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software2

Campaigns0

None recorded.

Procedure examples21

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwarePLAINTEE

PLAINTEE uses the ipconfig /all command to gather the victim’s IP address.

T1053.005
Scheduled Task
GroupRancor

Rancor launched a scheduled task to gain persistence using the schtasks /create /sc command.

T1057
Process Discovery
MalwarePLAINTEE

PLAINTEE performs the tasklist command to list running processes.

T1059.003
Windows Command Shell
GroupRancor

Rancor has used cmd.exe to execute commmands.

T1059.003
Windows Command Shell
MalwarePLAINTEE

PLAINTEE uses cmd.exe to execute commands on the victim’s machine.

T1059.005
Visual Basic
GroupRancor

Rancor has used VBS scripts as well as embedded macros for execution.

T1071.001
Web Protocols
GroupRancor

Rancor has used HTTP for C2.

T1082
System Information Discovery
MalwarePLAINTEE

PLAINTEE collects general system enumeration data about the infected machine and checks the OS version.

T1083
File and Directory Discovery
MalwareDDKONG

DDKONG lists files on the victim’s machine.

T1105
Ingress Tool Transfer
GroupRancor

Rancor has downloaded additional malware, including by using certutil.

T1105
Ingress Tool Transfer
MalwareDDKONG

DDKONG downloads and uploads files on the victim’s machine.

T1105
Ingress Tool Transfer
MalwarePLAINTEE

PLAINTEE has downloaded and executed additional plugins.

T1112
Modify Registry
MalwarePLAINTEE

PLAINTEE uses reg add to add a Registry Run key for persistence.

T1140
Deobfuscate/Decode Files or Information
MalwareDDKONG

DDKONG decodes an embedded configuration using XOR.

T1204.002
Malicious File
GroupRancor

Rancor attempted to get users to click on an embedded macro within a Microsoft Office Excel document to launch their malware.

T1218.007
Msiexec
GroupRancor

Rancor has used msiexec to download and execute malicious installer files over HTTP.

T1218.011
Rundll32
MalwareDDKONG

DDKONG uses Rundll32 to ensure only a single instance of itself is running at once.

T1547.001
Registry Run Keys / Startup Folder
MalwarePLAINTEE

PLAINTEE gains persistence by adding the Registry key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce.

T1548.002
Bypass User Account Control
MalwarePLAINTEE

An older variant of PLAINTEE performs UAC bypass.

T1566.001
Spearphishing Attachment
GroupRancor

Rancor has attached a malicious document to an email to gain initial access.

T1573.001
Symmetric Cryptography
MalwarePLAINTEE

PLAINTEE encodes C2 beacons using XOR.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.