Also known as: Rancor group, Rancor, Rancor Group, G0075, Rancor Taurus
Rancor is a threat group that has led targeted campaigns against the South East Asia region. Rancor uses politically-motivated lures to entice victims to open malicious documents. (Citation: Rancor Unit42 June 2018)
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Rancor is a government‑focused espionage group operating primarily against Southeast Asian nations. The group employs politically‑charged spear‑phishing lures to deliver malicious Office documents, aiming to exfiltrate sensitive state information. Their activity was first publicly documented by Unit42 in June 2018.
Goals & Targeting
Rancor’s strategic objective is the acquisition of political, diplomatic, and strategic intelligence from Southeast Asian governments. By focusing on ministries, defense agencies, and policy‑making bodies, the group seeks to gain insight into regional decision‑making processes, military planning, and foreign policy stances. Their typical victims are senior officials, policy analysts, and IT staff with privileged access, chosen because compromise of these accounts provides the most valuable data and the greatest potential for lateral movement within government networks.
Enhanced Description
Rancor, also known as Rancor Group, G0075, or Rancor Taurus, conducts targeted cyber‑espionage campaigns against governmental entities in Southeast Asia. The group crafts politically‑motivated lures—often referencing regional issues or elections—to entice recipients into opening weaponized Office documents. These documents typically embed malicious macros that execute PowerShell or Windows Script Host payloads, establishing a foothold on the victim’s network. Once initial access is achieved, Rancor leverages a blend of custom backdoors and publicly available tools to expand privileges, move laterally, and harvest credentials. Evidence suggests the use of credential‑dumping utilities such as Mimikatz, as well as remote access frameworks like Cobalt Strike for command‑and‑control. The actors appear to favor stealth, employing techniques like process injection, masquerading, and encrypted C2 traffic over common web protocols. Although the group’s full operational timeline remains unclear, the June 2018 Unit42 report indicates a sustained focus on Southeast Asian government ministries and agencies. Their campaigns are characterized by low‑volume, high‑value targeting, with infrastructure hosted on bullet‑proof services to evade takedown. The lack of publicly disclosed ransomware or financial extortion activities reinforces the espionage‑only motive. Rancor’s limited public footprint suggests a moderate level of sophistication—enough to develop tailored phishing lures and maintain custom malware, yet still reliant on off‑the‑shelf tools for many post‑exploitation steps. Continuous monitoring of spear‑phishing trends and macro‑based malware remains essential for defending against this actor.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Rancor’s known campaign, highlighted in the Unit42 June 2018 report, employed political narratives relevant to Southeast Asian audiences to increase click‑through rates. The operation used a low‑volume, high‑value approach, delivering malicious documents to a select list of government officials. Infrastructure was hosted on bullet‑proof providers, with domains frequently rotated to avoid detection. Subsequent activity appears sporadic, suggesting a focus on strategic intelligence gathering rather than continuous disruption. No ransomware or extortion behavior has been observed, reinforcing a pure espionage motive.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the current profile is moderate. The primary source is a single Unit42 report from 2018, and no additional open‑source or technical disclosures have emerged since. While the described TTPs align with known espionage groups, gaps remain regarding the actor’s full toolset, exact timeline of activity, and any evolution of tactics post‑2018. Continuous monitoring for new IOCs and further attribution research is recommended.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
9
Techniques
8
Tools
0
Campaigns
0
IOCs
0
Observed Data
5
Tactics