RANCOR__2019__Rancor_Cyber_Espionage_Group_Uses_New_Custom_Malware_to_Attack_Southeast_Asia.pdf
ID: 50873fe2-3bd2-4745-a79d-c06cdd5a259a
STIX ID: report--50873fe2-3bd2-4745-a79d-c06cdd5a259a
Threat Score
85/100
Uploaded: 2026-08-19
Published Date: 2019-12-18
Last Modified Date: 2019-12-18
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Rancor, a cyber espionage group active since at least 2017, conducted targeted attacks in Southeast Asia using a weaponized Excel macro (Dudell) to download second-stage payloads and employing multiple backdoors and loaders (KHRAT, Derusbi), a DDKONG plugin, and an obfuscated VBScript that installs persistence via MOF/WMI; the Unit 42 report provides sample metadata, behavioral analysis, C2 domains/IPs, and SHA256 IoCs for detection and mitigation.
