DDKONG is a Windows malware family associated with targeted intrusion activity linked to the Rancor threat cluster and observed in attacks in Southeast Asia. It has been documented alongside the PLAINTEE malware family in espionage-oriented operations. DDKONG includes embedded configuration data that it decodes at runtime using XOR, indicating basic obfuscation of operational parameters. It also abuses the trusted Windows utility rundll32.exe as part of its execution flow to help ensure only a single instance of the malware runs at a time, reflecting use of signed-binary proxy execution for operational control and defense evasion. The available reporting supports DDKONG as a DLL-based malware family used in targeted attacks, but does not provide sufficient high-confidence detail to characterize it more specifically than a trojan-class implant.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
The content is a long ATT&CK-style listing of malware and threat groups that 'decrypt', 'decode', 'deobfuscate', 'unpack', or 'decompress' payloads, strings, configuration data, shellcode, and files prior to execution or use.
Adversaries may abuse rundll32.exe to proxy execution of malicious code. Using rundll32.exe, vice executing directly (i.e. Shared Modules), may avoid triggering security tools that may not monitor execution of the rundll32.exe process because of allowlists or false positives from normal operations.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware that decodes embedded configuration data using XOR.
Malware that decodes embedded configuration data using XOR.
Malware family mentioned only in a cited reference about Rancor operations.
Malware family that leverages rundll32.exe during execution control.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.