LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G0075: Rancor

Rancor is a threat group that has led targeted campaigns against the South East Asia region. Rancor uses politically-motivated lures to entice victims to open malicious documents. [1]

EnterpriseG0075GroupObject v1.3Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Rancor matters as a targeted-campaign reference point: MITRE describes the group as using politically motivated lures and malicious documents against victims in Southeast Asia. For leaders, the practical lesson is not the name alone, but whether the organization can prevent, detect, and investigate document-driven initial access that leads into Windows command execution, persistence, tool transfer, and web-based command-and-control patterns.

Executive priority

Prioritize Rancor as a validation use case for phishing resilience, endpoint visibility, and incident response readiness where the organization has users, partners, executives, or operations exposed to politically themed targeting in Southeast Asia. The ATT&CK relationships emphasize common enterprise control questions: can the SOC see malicious attachment execution, signed Windows utilities used suspiciously, scheduled tasks, WMI persistence, and outbound web-protocol C2; and can incident responders quickly preserve host and email evidence for audit and containment decisions.

Technical view

The group object has no official detection text and no platform field, but the related techniques and software are heavily Windows-relevant: Reg, certutil, PLAINTEE, Scheduled Task, Windows Command Shell, Visual Basic, Msiexec, and WMI event subscription. Detection engineering should map coverage from spearphishing attachment and malicious file execution through post-execution behaviors: cmd activity, suspicious certutil or msiexec use, registry interaction, scheduled task creation, WMI event subscription artifacts, ingress tool transfer, and outbound HTTP/S-style command-and-control. Treat these as behavior-validation themes rather than indicators of Rancor attribution by themselves.

Likely telemetry

  • Email security logs and message metadata for spearphishing attachments and politically themed lures where available
  • Endpoint process creation telemetry for cmd.exe, msiexec.exe, certutil.exe, reg.exe, script or Visual Basic execution, and parent-child process context
  • Windows scheduled task creation and modification events
  • WMI event filter, consumer, and binding telemetry or forensic artifacts
  • Registry modification telemetry relevant to persistence or configuration changes

Detection direction

  • Validate detections across the full chain: malicious attachment delivery, user-opened file execution, command shell activity, persistence creation, tool transfer, and outbound web traffic.
  • Tune signed-utility detections carefully: certutil, reg, and msiexec have legitimate administrative uses, so prioritize suspicious command-line arguments, unusual parent processes, user context, destination patterns, and execution from user-writable paths.
  • Confirm that scheduled task and WMI persistence visibility is enabled and retained long enough for incident response timelines.
  • Use the Rancor relationships as threat-informed test cases, not as attribution rules; the same techniques and utilities are common across many adversaries and administrators.
  • Look for blind spots in email-to-endpoint correlation, especially where attachments are detonated in email tools but endpoint execution telemetry is incomplete.

Mitigation priorities

  • Strengthen phishing and attachment controls first: filtering, attachment analysis, user reporting workflows, and rapid mailbox search/removal procedures.
  • Harden endpoint execution paths by limiting unnecessary script, macro, installer, and command-line abuse opportunities consistent with business needs.
  • Restrict and monitor administrative utilities such as certutil, msiexec, reg, scheduled tasks, and WMI where feasible, focusing on least privilege and high-fidelity logging.
  • Ensure EDR and Windows logging cover process creation, command lines, scheduled tasks, WMI subscriptions, registry changes, and file downloads.
  • Prepare IR playbooks that connect email evidence, host triage, persistence checks, malware containment, and outbound network review.
Additional notes and limits

The most decision-useful aspect of this object is the relationship context: a targeted group associated with malicious documents and a set of techniques that span initial access, execution, persistence, stealth, and command-and-control. Rancor-specific confidence should depend on local evidence, such as matching malware, campaign artifacts, or intelligence from the cited reporting, not on generic use of Windows utilities alone.

MITRE provides no official detection section, no explicit tactics or platforms on the group object, and only a brief description. Several related techniques list platforms beyond Windows, but many connected tools and behaviors are Windows-oriented. This take therefore stays at the defensive validation level and does not assert active exploitation, victim exposure, or guaranteed detection coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Rancor

Rancor is a threat group that has led targeted campaigns against the South East Asia region. Rancor uses politically-motivated lures to entice victims to open malicious documents. [1]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

9 rows
DomainIDNameRelationship / procedure
EnterpriseT1071.001Web ProtocolsSub-technique

Rancor has used HTTP for C2.[1]

EnterpriseT1059.005Visual BasicSub-technique

Rancor has used VBS scripts as well as embedded macros for execution.[1]

EnterpriseT1204.002Malicious FileSub-technique

Rancor attempted to get users to click on an embedded macro within a Microsoft Office Excel document to launch their malware.[1]

EnterpriseT1053.005Scheduled TaskSub-technique

Rancor launched a scheduled task to gain persistence using the schtasks /create /sc command.[1]

EnterpriseT1105Ingress Tool Transfer

Rancor has downloaded additional malware, including by using certutil.[1]

EnterpriseT1218.007MsiexecSub-technique

Rancor has used msiexec to download and execute malicious installer files over HTTP.[1]

EnterpriseT1546.003Windows Management Instrumentation Event SubscriptionSub-technique

Rancor has complied VBScript-generated MOF files into WMI event subscriptions for persistence.[2]

EnterpriseT1059.003Windows Command ShellSub-technique

Rancor has used cmd.exe to execute commmands.[1]

EnterpriseT1566.001Spearphishing AttachmentSub-technique

Rancor has attached a malicious document to an email to gain initial access.[1]

Associated objects

Groups, software, and campaigns

ToolEnterprise

S0075: Reg

Reg is a Windows utility used to interact with the Windows Registry. It can be used at the command-line interface to query, add, modify, and remove information. [1]

Utilities such as Reg are known to be used by persistent threats. [2]

Windows
ToolEnterprise

S0160: certutil

certutil is a command-line utility that can be used to obtain certificate authority information and configure Certificate Services. [1]

Windows
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.3
Created
Modified
Raw hash
c339a4b192ac097c...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.3Current bundlec339a4b192ac…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Rancor Unit42 June 2018

    Ash, B., et al. (2018, June 26). RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families. Retrieved July 2, 2018.

    Open source URL
  2. [2]
    Rancor WMI

    Jen Miller-Osborn and Mike Harbison. (2019, December 17). Rancor: Cyber Espionage Group Uses New Custom Malware to Attack Southeast Asia. Retrieved February 9, 2024.

    Open source URL
  3. [3]
    Rancor

    (Citation: Rancor Unit42 June 2018)

  4. [4]
    Rancor

    (Citation: Rancor Unit42 June 2018)

  5. [5]
    Rancor

    (Citation: Rancor Unit42 June 2018)

  6. [6]
    Rancor Unit42 June 2018

    Ash, B., et al. (2018, June 26). RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families. Retrieved July 2, 2018.

    Open source URL
  7. [7]
    Rancor Unit42 June 2018

    Ash, B., et al. (2018, June 26). RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families. Retrieved July 2, 2018.

    Open source URL
  8. [8]
    mitre-attackG0075
    Open source URL
  9. [9]
    mitre-attackG0075
    Open source URL
  10. [10]
    mitre-attackG0075
    Open source URL
  11. [11]
    Rancor Unit42 June 2018

    Ash, B., et al. (2018, June 26). RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families. Retrieved July 2, 2018.

    Open source URL
  12. [12]
    Rancor Unit42 June 2018

    Ash, B., et al. (2018, June 26). RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families. Retrieved July 2, 2018.

    Open source URL
  13. [13]
    Rancor Unit42 June 2018

    Ash, B., et al. (2018, June 26). RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families. Retrieved July 2, 2018.

    Open source URL
  14. [14]
    Rancor Unit42 June 2018

    Ash, B., et al. (2018, June 26). RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families. Retrieved July 2, 2018.

    Open source URL
  15. [15]
    Rancor Unit42 June 2018

    Ash, B., et al. (2018, June 26). RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families. Retrieved July 2, 2018.

    Open source URL
  16. [16]
    Rancor Unit42 June 2018

    Ash, B., et al. (2018, June 26). RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families. Retrieved July 2, 2018.

    Open source URL
  17. [17]
    Rancor Unit42 June 2018

    Ash, B., et al. (2018, June 26). RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families. Retrieved July 2, 2018.

    Open source URL
  18. [18]
    Rancor Unit42 June 2018

    Ash, B., et al. (2018, June 26). RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families. Retrieved July 2, 2018.

    Open source URL
  19. [19]
    Rancor Unit42 June 2018

    Ash, B., et al. (2018, June 26). RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families. Retrieved July 2, 2018.

    Open source URL
  20. [20]
    Rancor Unit42 June 2018

    Ash, B., et al. (2018, June 26). RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families. Retrieved July 2, 2018.

    Open source URL
  21. [21]
    Rancor Unit42 June 2018

    Ash, B., et al. (2018, June 26). RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families. Retrieved July 2, 2018.

    Open source URL
  22. [22]
    Rancor Unit42 June 2018

    Ash, B., et al. (2018, June 26). RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families. Retrieved July 2, 2018.

    Open source URL
  23. [23]
    Rancor Unit42 June 2018

    Ash, B., et al. (2018, June 26). RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families. Retrieved July 2, 2018.

    Open source URL
  24. [24]
    Rancor Unit42 June 2018

    Ash, B., et al. (2018, June 26). RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families. Retrieved July 2, 2018.

    Open source URL
  25. [25]
    Rancor Unit42 June 2018

    Ash, B., et al. (2018, June 26). RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families. Retrieved July 2, 2018.

    Open source URL
  26. [26]
    Rancor Unit42 June 2018

    Ash, B., et al. (2018, June 26). RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families. Retrieved July 2, 2018.

    Open source URL
  27. [27]
    Rancor Unit42 June 2018

    Ash, B., et al. (2018, June 26). RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families. Retrieved July 2, 2018.

    Open source URL
  28. [28]
    Rancor Unit42 June 2018

    Ash, B., et al. (2018, June 26). RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families. Retrieved July 2, 2018.

    Open source URL
  29. [29]
    Rancor Unit42 June 2018

    Ash, B., et al. (2018, June 26). RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families. Retrieved July 2, 2018.

    Open source URL
  30. [30]
    Rancor Unit42 June 2018

    Ash, B., et al. (2018, June 26). RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families. Retrieved July 2, 2018.

    Open source URL
  31. [31]
    Rancor WMI

    Jen Miller-Osborn and Mike Harbison. (2019, December 17). Rancor: Cyber Espionage Group Uses New Custom Malware to Attack Southeast Asia. Retrieved February 9, 2024.

    Open source URL
  32. [32]
    Rancor Unit42 June 2018

    Ash, B., et al. (2018, June 26). RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families. Retrieved July 2, 2018.

    Open source URL
  33. [33]
    Rancor Unit42 June 2018

    Ash, B., et al. (2018, June 26). RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families. Retrieved July 2, 2018.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.