Hancitor
MITRE ATT&CK: S0499 View on attack.mitre.org
Aliases: Chanitor, Hancitor
- First seen
- 2013-09-01 00:00:00
- Malware type
- downloader
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 165 (145 malicious)
- Last IoC activity
- 2026-09-01 22:38:04
- Profile updated
- 2026-07-07 13:05:03
Targeted industries: financial-services healthcare-and-pharmaceutical technology-and-telecommunications
Targeted regions: country_code:us country_code:ca country_code:gb
Context
Hancitor is a downloader that has been used by Pony and other information stealing malware.
Recent IoC activity
145 malicious indicators in Maltiverse are attributed to Hancitor (S0499). The 20 most recently updated:
Detection coverage
- 2 YARA rules
- 458 Sigma rules
Malware & tools used
- Malicious File (attack-pattern)
- Verclsid (attack-pattern)
- Compression (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Malicious Link (attack-pattern)
- Native API (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- PowerShell (attack-pattern)
- Spearphishing Link (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- File Deletion (attack-pattern)
- Virtualization/Sandbox Evasion (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
Used by threat actors
- Moskalvzapoe (threat-actor)
Detection rules
- CAPE_Hancitor (yara-rule)
- MALPEDIA_Win_Hancitor_Auto (yara-rule)
Reports & references
- medium.com — Man1 Moskal Hancitor And A Side Of Ransomware D77B4D991618 (report)
- Palo Alto Unit 42 — Hancitor Infections Cobalt Strike (report)
- blog.group-ib.com — Hancitor Cuba Ransomware (report)
- blog.group-ib.com — Prometheus Tds (report)
- intel471.com — Cobalt Strike Cybercriminals Trickbot Qbot Hancitor (report)
- thedfirreport.com — Hancitor Continues To Push Cobalt Strike (report)
- malware-traffic-analysis.net — Index (report)
- isc.sans.edu — 27618 (report)
- thedfirreport.com — From Zero To Domain Admin (report)
- malware-traffic-analysis.net — Index (report)
- binarydefense.com — Analysis Of Hancitor When Boring Begets Beacon (report)
- twitter.com — 1359669513520873473 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Hancitor (report)
- muha2xmad.github.io — Hancitor (report)
- Mandiant — Hancitor Aka Chanit (report)
- github.com — Hancitor.Ipynb (report)
- isc.sans.edu — 26980 (report)
- researchcenter.paloaltonetworks.com — Unit42 Vb Dropper And Shellcode For Hancitor Reveal New Techniques Behind Uptick (report)
- researchcenter.paloaltonetworks.com — Unit42 Pythons And Unicorns And Hancitoroh My Decoding Binaries Through Emulation (report)
- elis531989.medium.com — Dissecting And Automating Hancitors Config Extraction 1A6Ed85D99B8 (report)
- blog.minerva-labs.com — New Hancitor Pimp My Downloader (report)
- muha2xmad.github.io — Fullhancitor (report)
- dodgethissecurity.com — Hancitor Evasive New Waves And How Com Objects Can Use Cached Credentials For Proxy Authentication (report)
- 0ffset.net — Reversing Hancitor Again (report)
- researchcenter.paloaltonetworks.com — Unit42 Compromised Servers Fraud Accounts Recent Hancitor Attacks (report)