logo

RANCOR__2019__Rancor_Cyber_Espionage_Group_Uses_New_Custom_Malware_to_Attack_Southeast_Asia.pdf

ID: 50873fe2-3bd2-4745-a79d-c06cdd5a259a

STIX ID: report--50873fe2-3bd2-4745-a79d-c06cdd5a259a

Threat Score

85/100

Uploaded: 2026-08-19

Published Date: 2019-12-18

Last Modified Date: 2019-12-18

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Rancor, a cyber espionage group active since at least 2017, conducted targeted attacks in Southeast Asia using a weaponized Excel macro (Dudell) to download second-stage payloads and employing multiple backdoors and loaders (KHRAT, Derusbi), a DDKONG plugin, and an obfuscated VBScript that installs persistence via MOF/WMI; the Unit 42 report provides sample metadata, behavioral analysis, C2 domains/IPs, and SHA256 IoCs for detection and mitigation.