Skip to main content
Skip to main content
Microsoft Security Intelligence
83 entries found. Displaying page 1 of 5.
Updated on Apr 07, 2021

Microsoft Defender Antivirus detects and removes this threat.

Hancitor, also known as Chanitor, is a malware designed to install other malware on targeted devices. Hancitor has been active since 2013, and was typically delivered as an attachment through spear-phishing emails with varying lure themes. However, from 2020 onwards, threat actors have been using DocuSign-themed lures to entice target users into opening links in emails, which then lead to another link that downloads a document with a malicious macro that contains the main Hancitor payload.

Once on the target device, Hancitor performs initial reconnaissance, connects to the attackers' command-and-control (C2) server, and downloads additional malware, including banking trojans like Zloader and Vawtrak, and information stealers like Pony and Ficker. In some campaigns, attackers have also used Hancitor to install Cobalt Strike or exploit CVE-2020-1472. In all these infections, Hancitor uses these tools to perform various malicious activities, including lateral movement, credential theft, and data exfiltration.

Alert level: severe
Updated on Dec 09, 2023
Alert level: severe
Updated on Apr 28, 2024
Alert level: severe
Updated on Jul 04, 2019
Alert level: severe
Updated on Nov 12, 2020
Alert level: severe
Updated on Apr 15, 2021
Alert level: severe
Updated on May 04, 2024
Alert level: severe
Updated on Jul 15, 2021
Alert level: severe
Updated on Apr 24, 2020
Alert level: severe
Updated on Sep 16, 2021
Alert level: severe
Updated on Mar 05, 2019
Alert level: severe
Updated on Aug 14, 2019
Alert level: severe
Updated on Nov 20, 2019
Alert level: severe
Updated on Dec 06, 2019
Alert level: severe
Updated on Dec 14, 2019
Alert level: severe
Updated on Nov 07, 2020
Alert level: severe
Updated on Nov 18, 2020
Alert level: severe
Updated on Dec 01, 2020
Alert level: severe
Updated on Dec 09, 2020
Alert level: severe
Updated on Dec 12, 2020
Alert level: severe