RANCOR is a China-based threat actor targeting government entities in Singapore and Cambodia.
Analyst brief
RANCOR is a China-based nation-state cyber threat actor. It primarily targets government and civil society organizations in Singapore and Cambodia. Their key TTPs include initial access via `Spearphishing Attachment` (T1566.001) to deliver the `DDKONG` and `PLAINTEE` malware, leveraging `Windows Management Instrumentation Event Subscription` for privilege escalation, and using `Web Protocols` for C2. Defenders should focus on monitoring email-borne threats, the execution of suspicious `.vbs` files, and the anomalous use of `Msiexec` alongside system tools like `Reg` and `certutil`.
RANCOR
Rancor groupRancorRancor Group
nation-state
The Rancor group’s attacks use two primary malware families which are naming DDKONG and PLAINTEE. DDKONG is used throughout the campaign and PLAINTEE appears to be new addition to these attackers’ toolkit. Countries Unit 42 has identified as targeted by Rancor with these malware families include, but are not limited to Singapore and Cambodia.
origin (suspected)
🇨🇳China· state-sponsoredattribution confidence: medium (50)