CNChinaconfidence: 50G0075

RANCORRANCOR

Also known as: Rancor group · Rancor · Rancor Group · G0075 · Rancor Taurus

Origin
CN
Known aliases
5
Target sectors
2
Attribution
State-sponsored

Profile

The Rancor group’s attacks use two primary malware families which are naming DDKONG and PLAINTEE. DDKONG is used throughout the campaign and PLAINTEE appears to be new addition to these attackers’ toolkit. Countries Unit 42 has identified as targeted by Rancor with these malware families include, but are not limited to Singapore and Cambodia.

Aliases· 5

Rancor groupRancorRancor GroupRancor Taurus
G0075

Target sectors· 2

GovernmentCivil society

Known victims· 2

  • Singapore
  • Cambodia

MITRE ATT&CK Group crosswalk

G0075

References

  1. https://unit42.paloaltonetworks.com/unit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families/
  2. https://www.cfr.org/interactive/cyber-operations/rancor
  3. https://attack.mitre.org/groups/G0075/
  4. https://unit42.paloaltonetworks.com/atoms/rancortaurus/

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
PLAINTEE
Software
DDKONG
Actor
Naikon
Actor
APT45
Actor
DAGGER PANDA
Actor
RAZOR TIGER
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.