AdversaryGraph public intelligence page
This page is part of Threat Matrix, the public browser workspace for the main AdversaryGraph platform. Use it for ATT&CK pivots, actor and technique context, similarity leads, detection coverage review, and analyst-ready investigation paths.
Validation disclaimer: TTP overlap, actor similarity, generated summaries, and coverage findings are investigation leads, not attribution proof or operational validation without analyst review.
Main AdversaryGraph project Documentation Malware Analysis GitHub
Rancor
Aliases: None listed
Rancor is a threat group that has led targeted campaigns against the South East Asia region. Rancor uses politically-motivated lures to entice victims to open malicious documents.
Open interactive actor investigation
ATT&CK techniques
Correlated CTI and IR reports
Continue the investigation
Cyber Knowledge routes
These contextual routes explain behaviors associated with this ATT&CK group record. They support learning and investigation planning; they do not add attribution evidence.
Red Team & Offensive Security · explicit-nameModule 7 — Endpoint defense and EDR
Blue Team & Defensive Security · explicit-nameControlled dynamic behavior and differential observation
Malware Analysis & Reverse Engineering · explicit-nameWindows endpoint and identity forensics
Digital Forensics & Incident Response (DFIR) · explicit-namePrompt injection, instruction hierarchy, and secure output handling
AI Security · topic-matchDebugging, tracing, and runtime instrumentation
Malware Analysis & Reverse Engineering · topic-matchModule 2 — The Intelligence Cycle Intelligence Types
Cyber Threat Intelligence (CTI) · topic-matchModule 8 — Operationalizing CTI (CTI → Detection)
Cyber Threat Intelligence (CTI) · topic-matchDisassembly, decompilation, and code-led analysis
Malware Analysis & Reverse Engineering · topic-matchCloud, SaaS, identity, container, and Kubernetes forensics
Digital Forensics & Incident Response (DFIR) · topic-matchWeakness taxonomy and vulnerability identity
Vulnerability Research & Exploit Development · topic-matchInput boundaries, injection prevention, and safe output
Secure Code & Application Security · topic-match