All actors

Rancor

Also reported as Rancor Group, Rancor Taurus, RANCOR and Rancor group. Linked to China by three sources.

Reports
37
Last reported
Known CVEs
26
Techniques in ATT&CK
9
Origin
China
ID
G0075
Merge evidence
7 alias matches

Reports per quarter

  1. 2018 Q2: 4 reports
  2. 2018 Q3: 2 reports
  3. 2018 Q4: 1 report
  4. 2019 Q1: 2 reports
  5. 2019 Q2: no reports
  6. 2019 Q3: 5 reports
  7. 2019 Q4: 3 reports
  8. 2020 Q1: 7 reports
  9. 2020 Q2: 2 reports
  10. 2020 Q3: no reports
  11. 2020 Q4: no reports
  12. 2021 Q1: 3 reports
  13. 2021 Q2: 1 report
  14. 2021 Q3: no reports
  15. 2021 Q4: 1 report
  16. 2022 Q1: no reports
  17. 2022 Q2: 2 reports
  18. 2022 Q3: 2 reports
  19. 2022 Q4: no reports
  20. 2023 Q1: 1 report
  21. 2023 Q2: 1 report
Dated reports, 2018 Q2 to 2023 Q2.

Techniques in ATT&CK

Listed by ATT&CK

No report from the last two years names a technique ID.

CVEs named in reports

Show all 26 CVEs Show fewer

KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.

Reports

Show all 37 reports Show fewer
  1. An Overhead View of the Royal Road

    date in the title fromORKL

  2. Rancor_ Cyber Espionage Group Uses New Custom Malware to Attack Southeast Asia

    date in the CCS '25 data Palo Alto fromORKLCCS '25 data

  3. Rancor- The Year of The Phish

    date in the title fromORKL

  4. RANCOR APT_ Suspected targeted attacks against South East Asia

    date in the CCS '25 data MeltX0R Security fromORKLCCS '25 data

  5. Accenture Strategy Templates

    Malpedia library date fromORKL

Newest first. Details opens the report in Explore.