Hancitor is a malware operation and access-enablement threat actor best known for distributing malicious spam at scale to deliver malware and provide initial access to downstream criminal partners. It has been associated with phishing campaigns using themed lures such as business-document and e-signature notifications to compromise victims and establish footholds in corporate environments. Hancitor has been referenced as a spam-operator partner for other financially motivated intrusion sets, including use in campaigns that enabled Cuba ransomware access to enterprise networks through phishing emails. Based on available reporting, Hancitor’s most clearly supported role is large-scale initial access via malspam rather than operation of a ransomware brand itself. Its observed tradecraft includes phishing-based delivery and intrusion enablement for follow-on activity by partner groups. The available facts here do not directly support more specific attribution to a country of origin, a broader victim geography, or a fuller capability set beyond initial access through spam-driven phishing campaigns.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a partner used by Cuba for spam-delivered phishing access to corporate networks.
Mentioned only as an example of a large-scale malspam distribution partner that other groups may use to increase infection volume.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.