Rancor is an espionage-focused threat group active since at least 2017 and assessed with moderate confidence to be China-linked. The group has targeted government entities in Southeast Asia, with confirmed activity against organizations in Singapore and Cambodia and a later sustained campaign against Southeast Asian government bodies. Rancor commonly relies on spearphishing emails carrying malicious attachments, including Microsoft Office documents and weaponized RTF files, and uses politically or government-themed decoy content to increase credibility. Rancor tradecraft includes malicious macros, VBScript and JavaScript-based execution chains, abuse of document metadata and properties to conceal commands, exploitation of Microsoft Equation Editor vulnerabilities via RoyalRoad-style weaponized RTF documents, and user-execution lures that prompt victims to enable macros or open attachments. The group has used scheduled tasks for persistence, including repeated task creation attempts and privilege-oriented task registration, and has abused native Windows utilities such as msiexec, certutil, and cmd.exe during execution and payload staging. Observed command-and-control has used HTTP. Later Rancor intrusion chains evolved beyond macro-delivered scripts to include DLL side-loading with legitimate security software binaries, loader DLLs that invoke exported routines, PowerShell backdoors, and deployment of additional second-stage tooling including Cobalt Strike Beacon in at least one cluster. Reporting has also associated Rancor with RoyalRoad weaponization patterns shared among multiple China-linked intrusion sets. Overall, Rancor is characterized by iterative spearphishing-led intrusion campaigns against public-sector targets, modular follow-on payload delivery, persistence through scheduled tasks, and defense-evasion through signed binary proxy execution and DLL side-loading.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
30 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
RoyalRoad is a tool that generates weaponized RTF documents that exploit the following vulnerabilities in Microsoft’s Equation Editor: CVE-2017-11882, CVE-2018-0798 and CVE-2018-0802.
RoyalRoad is a tool that generates weaponized RTF documents that exploit the following vulnerabilities in Microsoft’s Equation Editor: CVE-2017-11882, CVE-2018-0798 and CVE-2018-0802.
RoyalRoad is a tool that generates weaponized RTF documents that exploit the following vulnerabilities in Microsoft’s Equation Editor: CVE-2017-11882, CVE-2018-0798 and CVE-2018-0802.
123 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as an associated threat actor in detection annotations for Ghostscript exploitation; no specific campaign activity is described in this reference.
Listed as a threat actor associated with the malicious file execution technique detected by this analytic.
Listed as a threat actor associated with Windows Command Shell execution behavior relevant to this detection.
Listed in the detection annotations as a threat actor associated with EFI volume mounting / installation-related behavior.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.