logo

RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families

ID: 7676833c-cb05-48e5-a31e-9645c4da7ea8

STIX ID: report--7676833c-cb05-48e5-a31e-9645c4da7ea8

Threat Score

88/100

Uploaded: 2026-08-19

Published Date: 2018-06-29

Last Modified Date: 2018-06-29

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
### Executive summary: The report from Unit 42 documents a targeted espionage campaign named RANCOR operating in South East Asia that uses two primary malware families — DDKONG (TCP-based beaconing, plugin architecture) and PLAINTEE (custom XOR-encoded UDP protocol) — delivered via spear-phishing decoys, malicious Office macros, HTA and DLL loaders; it maps infrastructure into two clusters, provides behavior and persistence details, and lists extensive IoCs (hashes, domains, IPs, mutexes) and mitigation guidance.