Alpha Cyber

The Year of The Phish: How Rancor Targets Your Business

In 2019, a sophisticated cyber threat group known as Rancor made headlines with an innovative and devastating phishing campaign.

Alpha Cyber Research3 min readupdated 1 Apr 2026
Rancor APT 2 Groups

Exposing Rancor: The Year of The Phish A Wake Up Call for Cybersecurity

In 2019, a sophisticated cyber threat group known as Rancor made headlines with an innovative and devastating phishing campaign. Dubbed “The Year of The Phish,” this attack targeted businesses, governments, and organizations worldwide using advanced techniques to exploit vulnerabilities and gain access to sensitive data. As phishing attacks continue to evolve, it’s crucial for businesses to stay one step ahead.

At Alpha Cyber, we specialize in mapping cyber threats, identifying the attack vectors, and building proactive defenses for our clients. By exposing the tactics and infrastructure behind Rancor’s operations, we can help you understand the importance of securing your network and mitigate future risks.

What Was Rancor?

Rancor’s phishing based attacks used a multistage approach, with Cobalt Strike loaders and Command and Control (C&C) servers facilitating a highly automated and stealthy attack lifecycle. The group’s persistence in evolving their methods made it particularly dangerous for any business or entity that wasn’t properly safeguarded. Phishing emails were used to deliver malicious payloads, and from there, attackers gained initial access before deploying Cobalt Strike to further compromise the network.

By mapping the infrastructure behind these attacks, we can pinpoint the key indicators of compromise (IOCs) that will help your organization stay protected. Early detection of these indicators can stop a potential attack before it escalates.

Rancor’s Tactics and Infrastructure

Rancor APT Years of the Phish Graph

Rancor used Cobalt Strike loaders to infect their victims, establishing a network of C&C servers that acted as hubs for command and control. These servers were often registered on dynamic DNS providers, making them difficult to block without up to date intelligence. In addition, the phishing emails that initiated the attack were carefully crafted to bypass security filters, further complicating defense efforts.

The good news? You can block these threats with the right security posture and real time monitoring.

Key Indicators of Compromise (IOCs)

Below are some of the IOCs that were part of Rancor’s infrastructure. Blocking these addresses, domains, and file hashes is essential to safeguarding your network.

Indicator TypeDetails
CobaltStrike Loader Hashe92d36a2d3f1cb4ac8ce9321869ab2e85d9525da
C&C Server Domain 1charleseedwards.dynamic-dns[.]net
C&C Server Domain 2www.sfstnksfcv.jungleheart[.]com
C&C Server Domain 3oui6473rf.xxuz[.]com
C&C Server Domain 4vvcxvsdvx.dynamic-dns[.]net
C&C Server Domain 5kibistation.onmypc[.]net
C&C Server Domain 6www.754d56-8523.sexidude[.]com
C&C Server Domain 7nicetiss54.lflink[.]com
C&C Server Domain 8dsdfdscxcv.justdied[.]com
C&C Server Domain 9www.dsgsdgergrfv.toythieves[.]com
IP Address 1185.234.73[.]4
IP Address 2154.16.37[.]122
IP Address 3152.89.161[.]19
IP Address 445.125.65[.]76

These IOCs are a starting point for blocking malicious traffic, but the key to defense is continuous monitoring and adapting to the evolving tactics of attackers. Our experts use real time intelligence to keep your defenses ahead of threats like Rancor.

How We Help You Defend Against Rancor and Other Threats

At Alpha Cyber, we leverage cutting edge tools and techniques to protect your organization. We provide:

Threat Intelligence & Monitoring: Proactively identifying emerging threats such as Rancor and adapting defenses to block them.
Phishing Detection & Prevention: Implementing advanced systems to catch phishing attempts before they compromise your network.
Incident Response & Remediation: Quickly identifying and mitigating any breaches to minimize damage.
Security Awareness Training: Educating your staff about phishing threats, ensuring they are the first line of defense.

Don’t Wait Until It’s Too Late

Cyber threats like Rancor are constantly evolving, and so should your cybersecurity strategy. If you’re not actively protecting your organization from phishing attacks and other threats, you could be the next target.

Reach out to us today and let us help you map, block, and defend your network with the best in class cybersecurity services. Together, we can make sure your business stays protected from the year of the phish and beyond.

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]