RANCOR__2019__RANCOR_APT_Suspected_targeted_attacks_against_South_East_Asia.pdf
ID: bab9e79b-1899-487f-b146-c0784b0d1369
STIX ID: report--bab9e79b-1899-487f-b146-c0784b0d1369
Threat Score
85/100
Uploaded: 2026-08-19
Published Date: 2019-09-12
Last Modified Date: 2019-09-12
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report details suspected Rancor APT activity targeting Southeast Asian (Cambodian) government entities via malicious RTF documents that exploit CVE-2018-0798 to drop a temporary payload which downloads a second-stage backdoor (likely DDKONG or PLAINTEE). The analysis outlines the exploitation chain, persistence mechanisms (scheduled tasks, certutil usage, VBScript), and provides IoCs including MD5 hashes and an IP used to serve the payload.
