The cyber-espionage group Rancor was reported using new custom malware to target organizations in Southeast Asia, expanding a long-running intrusion set focused on regional victims. The activity was attributed to espionage operations rather than financially motivated crime, with attackers relying on tailored malware and campaign-specific tooling to gain access and maintain a foothold in targeted environments.
The reporting indicates that Rancor continued to refine its tradecraft by introducing previously unseen malware in attacks against entities in the region, underscoring the group’s persistence and operational development. For defenders, the activity highlights the ongoing risk from state-aligned or espionage-focused actors that adapt malware families and intrusion methods to sustain access to government and other strategically relevant targets in Southeast Asia.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Palo Alto Networks Unit 42 published research describing the cyber-espionage group Rancor using new custom malware to target organizations in Southeast Asia. The report publicly documented the campaign and its tooling.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.