RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families
ID: 7676833c-cb05-48e5-a31e-9645c4da7ea8
STIX ID: report--7676833c-cb05-48e5-a31e-9645c4da7ea8
Threat Score
88/100
Uploaded: 2026-08-19
Published Date: 2018-06-29
Last Modified Date: 2018-06-29
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
### Executive summary: The report from Unit 42 documents a targeted espionage campaign named RANCOR operating in South East Asia that uses two primary malware families — DDKONG (TCP-based beaconing, plugin architecture) and PLAINTEE (custom XOR-encoded UDP protocol) — delivered via spear-phishing decoys, malicious Office macros, HTA and DLL loaders; it maps infrastructure into two clusters, provides behavior and persistence details, and lists extensive IoCs (hashes, domains, IPs, mutexes) and mitigation guidance.
