DDKONG

S0255

Malware.View on attack.mitre.org

About this malware

DDKONG is a malware sample that was part of a campaign by Rancor. DDKONG was first seen used in February 2017.

Techniques used4

Procedure examples4

TechniqueProcedure example
T1083
File and Directory Discovery

DDKONG lists files on the victim’s machine.

T1105
Ingress Tool Transfer

DDKONG downloads and uploads files on the victim’s machine.

T1140
Deobfuscate/Decode Files or Information

DDKONG decodes an embedded configuration using XOR.

T1218.011
Rundll32

DDKONG uses Rundll32 to ensure only a single instance of itself is running at once.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Rancor Unit42 June 2018 Open source
    Ash, B., et al. (2018, June 26). RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families. Retrieved July 2, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.