The Rancor threat group conducted a sustained espionage campaign against government entities in Southeast Asia, using spear-phishing emails that impersonated officials and carried politically themed decoy documents. Researchers tied the activity to operations spanning late 2018 through mid-2019, with attackers exploiting Microsoft Equation Editor flaws including CVE-2018-0798 and using malicious macros to gain initial access. Reporting also linked the campaign to earlier Rancor intrusions in the region involving the PLAINTEE and DDKONG malware families.
The operation evolved across multiple clusters, shifting from macro-delivered VBScript and PowerShell payloads to more advanced tradecraft such as DLL side-loading with legitimate antivirus executables and, in at least one case, Cobalt Strike Beacon. Attribution to Rancor was supported by overlapping infrastructure, loaders, metadata, persistence methods, and known command-and-control indicators, while separate research noted that multiple Chinese threat groups were exploiting the same Equation Editor vulnerability during the same period; Check Point assessed this campaign may be of Chinese origin based on language artifacts, operator working hours, use of the 8.t exploit builder, and an operational pause during Lunar New Year.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
Check Point disclosed a seven-month espionage campaign against Southeast Asian government entities and attributed it to the Rancor threat group. The report linked the activity to prior Rancor infrastructure and assessed that the operation may be of Chinese origin based on artifacts, infrastructure timing, tooling, and an operational pause during Chinese New Year.
Across May and June 2019, clusters five through eight added further infection chains, including one that deployed Cobalt Strike Beacon as a second-stage payload. Later variants also abused a legitimate Bitdefender executable from GitHub and downloaded internal plugins named nbf.plugin and nbs.plugin.
In May 2019, a fourth cluster used Equation Editor exploit documents to drop a legitimate Avast executable and a malicious DLL for side-loading. The DLL served as a loader for another DLL that executed the exported function RunningThread.
In April 2019, Check Point observed a third cluster using malicious RTF documents that exploited Microsoft Equation Editor vulnerabilities. The exploit chain dropped VBS and PowerShell files under C:\Windows\tracing to preserve the same command execution and C2 behavior.
In January and March 2019, the second observed cluster removed the MSI stage and used macros that decoded a base64 blob into a JavaScript file. The payload acted as a PowerShell backdoor and used repeated scheduled-task creation, including an attempt to run as SYSTEM.
In December 2018, Check Point observed the first cluster of a targeted espionage campaign against Southeast Asian government entities. Spear-phishing documents used malicious macros to run hidden commands, drop a VBScript, create scheduled tasks, and fetch an MSI-wrapped PowerShell backdoor.
Unit 42 reported that the Rancor threat group was conducting targeted attacks in Southeast Asia using the PLAINTEE and DDKONG malware families. This establishes Rancor activity in the region prior to the later 2018–2019 campaign.
Anomali reported that multiple Chinese threat groups had been exploiting CVE-2018-0798 in Microsoft Equation Editor since late 2018. This provides broader context for the exploit technique later seen in Rancor-linked activity.
3 references tracked. Mallory keeps watching after this page renders.
research.checkpoint.com
Open sourceanomali.com
Open sourceunit42.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.