Hancitor

MITRE ATT&CK: S0499 View on attack.mitre.org

Aliases: Chanitor, Hancitor

First seen
2013-09-01 00:00:00
Malware type
downloader
Family
Malware family
Operating systems
windows
Related IoCs
165 (145 malicious)
Last IoC activity
2026-09-01 22:38:04
Profile updated
2026-07-07 13:05:03

Targeted industries: financial-services healthcare-and-pharmaceutical technology-and-telecommunications

Targeted regions: country_code:us country_code:ca country_code:gb

Context

Hancitor is a downloader that has been used by Pony and other information stealing malware.

Recent IoC activity

145 malicious indicators in Maltiverse are attributed to Hancitor (S0499). The 20 most recently updated:

Detection coverage

  • 2 YARA rules
  • 458 Sigma rules

Malware & tools used

  • Malicious File (attack-pattern)
  • Verclsid (attack-pattern)
  • Compression (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Malicious Link (attack-pattern)
  • Native API (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • PowerShell (attack-pattern)
  • Spearphishing Link (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • File Deletion (attack-pattern)
  • Virtualization/Sandbox Evasion (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)

Used by threat actors

Detection rules

  • CAPE_Hancitor (yara-rule)
  • MALPEDIA_Win_Hancitor_Auto (yara-rule)

Reports & references

  • medium.com — Man1 Moskal Hancitor And A Side Of Ransomware D77B4D991618 (report)
  • Palo Alto Unit 42 — Hancitor Infections Cobalt Strike (report)
  • blog.group-ib.com — Hancitor Cuba Ransomware (report)
  • blog.group-ib.com — Prometheus Tds (report)
  • intel471.com — Cobalt Strike Cybercriminals Trickbot Qbot Hancitor (report)
  • thedfirreport.com — Hancitor Continues To Push Cobalt Strike (report)
  • malware-traffic-analysis.net — Index (report)
  • isc.sans.edu — 27618 (report)
  • thedfirreport.com — From Zero To Domain Admin (report)
  • malware-traffic-analysis.net — Index (report)
  • binarydefense.com — Analysis Of Hancitor When Boring Begets Beacon (report)
  • twitter.com — 1359669513520873473 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Hancitor (report)
  • muha2xmad.github.io — Hancitor (report)
  • Mandiant — Hancitor Aka Chanit (report)
  • github.com — Hancitor.Ipynb (report)
  • isc.sans.edu — 26980 (report)
  • researchcenter.paloaltonetworks.com — Unit42 Vb Dropper And Shellcode For Hancitor Reveal New Techniques Behind Uptick (report)
  • researchcenter.paloaltonetworks.com — Unit42 Pythons And Unicorns And Hancitoroh My Decoding Binaries Through Emulation (report)
  • elis531989.medium.com — Dissecting And Automating Hancitors Config Extraction 1A6Ed85D99B8 (report)
  • blog.minerva-labs.com — New Hancitor Pimp My Downloader (report)
  • muha2xmad.github.io — Fullhancitor (report)
  • dodgethissecurity.com — Hancitor Evasive New Waves And How Com Objects Can Use Cached Credentials For Proxy Authentication (report)
  • 0ffset.net — Reversing Hancitor Again (report)
  • researchcenter.paloaltonetworks.com — Unit42 Compromised Servers Fraud Accounts Recent Hancitor Attacks (report)

External references