Skip to content

Hancitor

Hancitor, also known as Chanitor, is a Windows malware loader and downloader that has been widely used as an initial access payload in financially motivated intrusion activity.

Profile source: Mallory opens in a new tab

Hancitor

Family profile

Hancitor, also known as Chanitor, is a Windows malware loader and downloader that has been widely used as an initial access payload in financially motivated intrusion activity. It is commonly distributed through phishing and malspam campaigns using social-engineering lures such as invoices, billing notices, contracts, receipts, and similar business-themed messages. Delivery has frequently relied on malicious Microsoft Word documents that prompt victims to enable macros, and some campaigns have also used archive-contained executables or alternate attachment formats. Hancitor has been associated with TA511 activity and has served as an entry point for follow-on malware and broader intrusion operations, including ransomware-related compromises.

Hancitor’s infection chains have used VBA macros, embedded objects, shellcode execution, and PowerShell-based execution. Document-based droppers have decoded embedded payload material, allocated executable memory through native Windows APIs, and transferred execution to shellcode running inside Office processes. Other observed chains used multi-stage Word documents that dropped and executed DLL payloads through rundll32. Hancitor has also been observed decoding Base64-encoded content and extracting executables from ZIP archives as part of staging and delivery.

Once executed, Hancitor functions primarily as a downloader or loader for additional malware. Reported follow-on payloads have included Pony, Vawtrak, Cobalt Strike beacons, FickerStealer, and malware associated with Cuba and Zeppelin ransomware operations. In broader intrusion reporting, Hancitor has been identified alongside other initial access malware families that frequently precede hands-on-keyboard post-exploitation and ransomware deployment.

On infected Windows systems, Hancitor has used PowerShell to execute commands and has established persistence through Registry Run keys. Its droppers have also demonstrated defense-evasion and anti-forensics behavior, including deletion of files used during execution. Technical analyses have documented use of native APIs such as CallWindowProc and EnumResourceTypesA to interpret and execute shellcode, reflecting a design focused on in-memory staging and flexible payload delivery.

Capabilities

  • Defense Evasion
  • Initial Access
  • Persistence
  • Post Exploitation

Observed infrastructure

Last seven days

First activity
Sep 17, 2026
Last activity
Sep 17, 2026
Feed role
C2
Host form
0 IP / 3 hostnames

Samples

Recent associated samples

Reported operators

Threat actors

6 named in public reporting
WIZARD SPIDER

"1873433027": "TA511/Hancitor - Stats uniques -> ips/hostnames: 36 publickeys: 29"

Threat Group-3390

"1873433027": "TA511/Hancitor - Stats uniques -> ips/hostnames: 36 publickeys: 29"

TA511

"1873433027": "TA511/Hancitor - Stats uniques -> ips/hostnames: 36 publickeys: 29"

Moskalvzapoe

Also known as Chanitor, Hancitor is malware used by a threat actor designated as MAN1, Moskalvzapoe or TA511. Hancitor establishes initial access on a vulnerable Windows host and sends additional malware.

MAN1

Also known as Chanitor, Hancitor is malware used by a threat actor designated as MAN1, Moskalvzapoe or TA511. Hancitor establishes initial access on a vulnerable Windows host and sends additional malware.

Nebulous Mantis

"Initially relying on the Hancitor loader, the group pivoted in mid-2022 to RomCom..."

Exploited software

Vulnerabilities linked to Hancitor

2 CVEs

MITRE ATT&CK

Hancitor in ATT&CK

53 distinct techniques

Techniques

53 techniques
T1566 Phishing T1055 Process Injection T1105 Ingress Tool Transfer T1566.002 Spearphishing Link T1071 Application Layer Protocol T1204.002 Malicious File T1059.005 Visual Basic T1059.001 PowerShell T1566.001 Spearphishing Attachment T1129 Shared Modules T1106 Native API T1140 Deobfuscate/Decode Files or Information T1204 User Execution T1070.004 File Deletion T1560 Archive Collected Data T1059 Command and Scripting Interpreter T1547.001 Registry Run Keys / Startup Folder T1053 Scheduled Task/Job T1036.003 Rename Legitimate Utilities T1083 File and Directory Discovery T1027.009 Embedded Payloads T1218.011 Rundll32 T1082 System Information Discovery T1027 Obfuscated Files or Information T1203 Exploitation for Client Execution T1497 Virtualization/Sandbox Evasion T1036 Masquerading T1574 Hijack Execution Flow T1016 System Network Configuration Discovery T1071.001 Web Protocols T1033 System Owner/User Discovery T1543 Create or Modify System Process T1620 Reflective Code Loading T1018 Remote System Discovery T1070 Indicator Removal T1559.001 Component Object Model T1497.001 System Checks T1055.001 Dynamic-link Library Injection T1055.012 Process Hollowing T1534 Internal Spearphishing T1482 Domain Trust Discovery T1027.002 Software Packing T1132 Data Encoding T1055.003 Thread Execution Hijacking T1001 Data Obfuscation T1059.003 Windows Command Shell T1057 Process Discovery T1059.006 Python T1112 Modify Registry T1059.007 JavaScript T1218.012 Verclsid T1204.001 Malicious Link T1027.015 Compression

Reporting

Research mentioning Hancitor

Aug 18
Cyble Blog Historic

Cyble - BianLian: New Ransomware Variant On The Rise

BianLian emerged as a Go-based ransomware family targeting organizations in manufacturing, education, healthcare, and BFSI, with victims reporting file encryption and double-extortion threats. The malware appends the .bianlian extension to encrypted files, drops a ransom note named "Look at this instruction.txt", and warns that allegedly stolen financial, client, business, technical, and personal data will be leaked within ten days unless payment is made through negotiations conducted over TOX Messenger and a Tor-based leak site. Technical analysis shows the malware was built to hinder detection and speed impact on victim systems. BianLian performs anti-analysis checks associated with MITRE ATT&CK T1497 virtualization and sandbox evasion, creates multiple threads to accelerate encryption, enumerates drives from A: through Z:, excludes selected files and folders from encryption, and deletes itself after execution. Its behavior also aligns with broader defense-evasion patterns such as executable obfuscation and packing captured in MITRE ATT&CK T1027.002, underscoring how the ransomware combines rapid file encryption with techniques intended to frustrate automated analysis and reverse engineering.

Dec 17
Telekom

A new way to encrypt CC server URLs | Deutsche Telekom

Check Point Research reported that a newer Smokeloader variant introduced multiple changes to improve stealth, evasion, and persistence. The malware was observed bypassing userland hooks by loading a duplicate copy of ntdll.dll, adding anti-VM and anti-debugging checks, changing its URL decoding routine and network connection structure, and modifying persistence by using startup .lnk files followed by delayed scheduled-task creation. The activity was tied to a broader campaign that targeted trezor.io through FakeDNS redirection and used DDoS plugins while also delivering the Azorult infostealer from fileboard.live. Researchers said C2 naming patterns, reused RC4 keys, and historical overlap with Amadey, AveMaria, and ServHelper campaigns suggest the operator behind this Smokeloader activity may be TA505.

Jul 9
Checkpoint Research

The 2019 Resurgence of Smokeloader - Check Point Research

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.