logo

RANCOR__2019__RANCOR_APT_Suspected_targeted_attacks_against_South_East_Asia.pdf

ID: bab9e79b-1899-487f-b146-c0784b0d1369

STIX ID: report--bab9e79b-1899-487f-b146-c0784b0d1369

Threat Score

85/100

Uploaded: 2026-08-19

Published Date: 2019-09-12

Last Modified Date: 2019-09-12

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report details suspected Rancor APT activity targeting Southeast Asian (Cambodian) government entities via malicious RTF documents that exploit CVE-2018-0798 to drop a temporary payload which downloads a second-stage backdoor (likely DDKONG or PLAINTEE). The analysis outlines the exploitation chain, persistence mechanisms (scheduled tasks, certutil usage, VBScript), and provides IoCs including MD5 hashes and an IP used to serve the payload.