Hancitor, also known as Chanitor, is a Windows malware loader and downloader used to deploy additional malicious payloads, including information stealers, banking trojans, remote access trojans, and ransomware. It has delivered Pony, Vawtrak, FickerStealer, Cobalt Strike beacons, Cuba ransomware, and Zeppelin ransomware. Cuba ransomware operators have used Hancitor to deploy ransomware on compromised systems.
Hancitor is commonly distributed through phishing and malspam containing malicious links or Microsoft Word attachments. Campaigns use invoice, billing, receipt, contract, fax, and DocuSign-themed lures to persuade recipients to open documents and enable macros. Some campaigns have delivered Excel XLL add-ins instead of Word documents. Document-based infection chains can use multiple stages, password-protected documents, embedded objects, and VBA macros to extract and execute the loader.
Execution techniques include PowerShell commands, native Windows API calls, and shellcode running within the Word process. Macro-based delivery components have decoded Base64-encoded shellcode, decrypted embedded executables, and invoked Windows callbacks to transfer execution to malicious code. Other chains launch a dropped DLL through the Windows DLL execution utility. Hancitor has also extracted executables from ZIP archives, established persistence through Windows registry autostart entries, and deleted files using VBA. Its principal role is to enable subsequent malware execution rather than perform the theft or encryption functions of its downstream payloads.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Used a tool to exploit CVE-2020-1472 (also known as “ZeroLogon”) to gain Domain Administrative privileges. This tool and its intrusion attempts have been reportedly related to Hancitor and Qbot.
campaigns on January 24, 2018 and January 25, 2018 used a different document format, Rich Text Format (RTF), that leveraged an exploit (CVE-2017-11882) to launch shellcode which executed a PowerShell command used to download the standard binary | Over the past two years, the Hancitor malware family has been a fairly regular nuisance... In this post, I’ll be diving into the technical inner-workings of their latest malware packer.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The actors distributed Cuba ransomware on compromised systems through Hancitor—a loader known for dropping or executing stealers, such as Remote Access Trojans (RATs) and other types of ransomware.
"1873433027": "TA511/Hancitor - Stats uniques -> ips/hostnames: 36 publickeys: 29"
"1873433027": "TA511/Hancitor - Stats uniques -> ips/hostnames: 36 publickeys: 29"
"1873433027": "TA511/Hancitor - Stats uniques -> ips/hostnames: 36 publickeys: 29"
Also known as Chanitor, Hancitor is malware used by a threat actor designated as MAN1, Moskalvzapoe or TA511. Hancitor establishes initial access on a vulnerable Windows host and sends additional malware.
Also known as Chanitor, Hancitor is malware used by a threat actor designated as MAN1, Moskalvzapoe or TA511. Hancitor establishes initial access on a vulnerable Windows host and sends additional malware.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
The eSentire Threat Intelligence team is tracking a recently identified campaign delivering Hancitor malware through malicious “HelloFax” emails.
APT19 used PowerShell commands to execute payloads... APT28 downloads and executes PowerShell scripts... APT29 has used encoded PowerShell scripts... | used PowerShell commands to execute payloads
When the document macro is executed, it will inject malicious code into a svchost.exe process.
Cuba ransomware actors use Hancitor as a tool to spread malicious files throughout a victim’s network.
The content is a MITRE ATT&CK-style listing of many malware families and threat groups using Windows/native OS APIs for execution, injection, discovery, anti-debugging, and other actions, ending with 'NtCreateProcess' and 'fork()'.
When the document macro is executed, it will inject malicious code into a svchost.exe process.
275 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
88 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a comparison point for similar bulletproof-hosting-backed delivery campaigns.
A downloader trojan delivered via phishing emails disguised as important documents and using .scr executables. It copies itself into the roaming profile, establishes persistence via the registry, communicates with TOR-backed C2 infrastructure through tor2web over SSL, beacons to /gate.php, retrieves host IP information, and downloads additional payloads for execution.
Loader used earlier in the intrusion chain prior to the group’s pivot to RomCom; used to deliver subsequent payloads.
Malware family used by the group since 2019 as part of their intrusion activity; the content does not provide additional functional detail beyond its use in targeting campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.