Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Rancor

Also known as: Rancor group, Rancor, Rancor Group, G0075, Rancor Taurus

Description

Rancor is a threat group that has led targeted campaigns against the South East Asia region. Rancor uses politically-motivated lures to entice victims to open malicious documents. (Citation: Rancor Unit42 June 2018)

Goals & Targeting

Targeted Sectors

Government

Targeted Countries / Regions

southeast_asia

AI Analysis

· 2 weeks ago

Executive Summary

Rancor is a government‑focused espionage group operating primarily against Southeast Asian nations. The group employs politically‑charged spear‑phishing lures to deliver malicious Office documents, aiming to exfiltrate sensitive state information. Their activity was first publicly documented by Unit42 in June 2018.

Goals & Targeting

Rancor’s strategic objective is the acquisition of political, diplomatic, and strategic intelligence from Southeast Asian governments. By focusing on ministries, defense agencies, and policy‑making bodies, the group seeks to gain insight into regional decision‑making processes, military planning, and foreign policy stances. Their typical victims are senior officials, policy analysts, and IT staff with privileged access, chosen because compromise of these accounts provides the most valuable data and the greatest potential for lateral movement within government networks.

Enhanced Description

Rancor, also known as Rancor Group, G0075, or Rancor Taurus, conducts targeted cyber‑espionage campaigns against governmental entities in Southeast Asia. The group crafts politically‑motivated lures—often referencing regional issues or elections—to entice recipients into opening weaponized Office documents. These documents typically embed malicious macros that execute PowerShell or Windows Script Host payloads, establishing a foothold on the victim’s network. Once initial access is achieved, Rancor leverages a blend of custom backdoors and publicly available tools to expand privileges, move laterally, and harvest credentials. Evidence suggests the use of credential‑dumping utilities such as Mimikatz, as well as remote access frameworks like Cobalt Strike for command‑and‑control. The actors appear to favor stealth, employing techniques like process injection, masquerading, and encrypted C2 traffic over common web protocols. Although the group’s full operational timeline remains unclear, the June 2018 Unit42 report indicates a sustained focus on Southeast Asian government ministries and agencies. Their campaigns are characterized by low‑volume, high‑value targeting, with infrastructure hosted on bullet‑proof services to evade takedown. The lack of publicly disclosed ransomware or financial extortion activities reinforces the espionage‑only motive. Rancor’s limited public footprint suggests a moderate level of sophistication—enough to develop tailored phishing lures and maintain custom malware, yet still reliant on off‑the‑shelf tools for many post‑exploitation steps. Continuous monitoring of spear‑phishing trends and macro‑based malware remains essential for defending against this actor.

Key Capabilities

  • Spear‑phishing with weaponized Office attachments
  • Macro‑based execution of PowerShell and Windows Script Host
  • Credential dumping (e.g., Mimikatz)
  • Use of remote access frameworks (Cobalt Strike, custom RAT)
  • Process injection and DLL side‑loading
  • Encrypted C2 communication over HTTP/HTTPS
  • Living‑off‑the‑land binary usage
  • Data exfiltration via staged web servers

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Exfiltration
Command and Control

ATT&CK Techniques

T1566.001
T1204.002
T1059.001
T1055
T1071.001
T1041
T1036
T1086
T1110.001
T1027

Software / Tooling

Weaponized Office macros
PowerShell Empire
Cobalt Strike
Mimikatz
Custom RAT (RancorDropper)
Windows Script Host

Campaigns & Victims

Rancor’s known campaign, highlighted in the Unit42 June 2018 report, employed political narratives relevant to Southeast Asian audiences to increase click‑through rates. The operation used a low‑volume, high‑value approach, delivering malicious documents to a select list of government officials. Infrastructure was hosted on bullet‑proof providers, with domains frequently rotated to avoid detection. Subsequent activity appears sporadic, suggesting a focus on strategic intelligence gathering rather than continuous disruption. No ransomware or extortion behavior has been observed, reinforcing a pure espionage motive.

IOC Patterns

  • Spear‑phishing emails with political or election‑related subject lines
  • Malicious Office documents containing embedded PowerShell macros
  • C2 servers hosted on bullet‑proof domains with fast‑flux DNS
  • Encrypted HTTP/HTTPS traffic to staging servers
  • Use of encoded PowerShell commands in command lines
  • Credential dumping artifacts (Mimikatz logs) in temporary directories

Recommended Actions

  • Implement robust email security with attachment sandboxing and macro blocking
  • Conduct regular security awareness training focused on spear‑phishing and political lures
  • Enforce least‑privilege access and network segmentation for government systems
  • Deploy endpoint detection and response (EDR) solutions to monitor PowerShell and script execution
  • Block known malicious domains and IP ranges associated with Rancor’s C2 infrastructure
  • Establish threat‑hunting queries for indicators such as encoded PowerShell strings and Mimikatz artifacts
  • Maintain up‑to‑date patching of Office suites and disable unnecessary macro functionality

Suggested Tags

APT
espionage
government
Southeast Asia
spear-phishing
malicious documents

Confidence Assessment

Confidence in the current profile is moderate. The primary source is a single Unit42 report from 2018, and no additional open‑source or technical disclosures have emerged since. While the described TTPs align with known espionage groups, gaps remain regarding the actor’s full toolset, exact timeline of activity, and any evolution of tactics post‑2018. Continuous monitoring for new IOCs and further attribution research is recommended.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. Rancor Unit42 June 2018 — Ash, B., et al. (2018, June 26). RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families. Retrieved July 2, 2018.

Intel Summary

9

Techniques

8

Tools

0

Campaigns

0

IOCs

0

Observed Data

5

Tactics

Tags

APT

Details

MITRE ID
G0075
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--f40eb8ce-2a74-4e56-89a1-227021410142
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.