Last seven days
- First activity
- Sep 17, 2026
- Last activity
- Sep 17, 2026
- Feed role
- C2
- Host form
- 0 IP / 3 hostnames
Hancitor, also known as Chanitor, is a Windows malware loader and downloader that has been widely used as an initial access payload in financially motivated intrusion activity.
Profile source: Mallory opens in a new tabHancitor
Hancitor, also known as Chanitor, is a Windows malware loader and downloader that has been widely used as an initial access payload in financially motivated intrusion activity. It is commonly distributed through phishing and malspam campaigns using social-engineering lures such as invoices, billing notices, contracts, receipts, and similar business-themed messages. Delivery has frequently relied on malicious Microsoft Word documents that prompt victims to enable macros, and some campaigns have also used archive-contained executables or alternate attachment formats. Hancitor has been associated with TA511 activity and has served as an entry point for follow-on malware and broader intrusion operations, including ransomware-related compromises.
Hancitor’s infection chains have used VBA macros, embedded objects, shellcode execution, and PowerShell-based execution. Document-based droppers have decoded embedded payload material, allocated executable memory through native Windows APIs, and transferred execution to shellcode running inside Office processes. Other observed chains used multi-stage Word documents that dropped and executed DLL payloads through rundll32. Hancitor has also been observed decoding Base64-encoded content and extracting executables from ZIP archives as part of staging and delivery.
Once executed, Hancitor functions primarily as a downloader or loader for additional malware. Reported follow-on payloads have included Pony, Vawtrak, Cobalt Strike beacons, FickerStealer, and malware associated with Cuba and Zeppelin ransomware operations. In broader intrusion reporting, Hancitor has been identified alongside other initial access malware families that frequently precede hands-on-keyboard post-exploitation and ransomware deployment.
On infected Windows systems, Hancitor has used PowerShell to execute commands and has established persistence through Registry Run keys. Its droppers have also demonstrated defense-evasion and anti-forensics behavior, including deletion of files used during execution. Technical analyses have documented use of native APIs such as CallWindowProc and EnumResourceTypesA to interpret and execute shellcode, reflecting a design focused on in-memory staging and flexible payload delivery.
Samples
Reported operators
"1873433027": "TA511/Hancitor - Stats uniques -> ips/hostnames: 36 publickeys: 29"
"1873433027": "TA511/Hancitor - Stats uniques -> ips/hostnames: 36 publickeys: 29"
"1873433027": "TA511/Hancitor - Stats uniques -> ips/hostnames: 36 publickeys: 29"
Also known as Chanitor, Hancitor is malware used by a threat actor designated as MAN1, Moskalvzapoe or TA511. Hancitor establishes initial access on a vulnerable Windows host and sends additional malware.
Also known as Chanitor, Hancitor is malware used by a threat actor designated as MAN1, Moskalvzapoe or TA511. Hancitor establishes initial access on a vulnerable Windows host and sends additional malware.
"Initially relying on the Hancitor loader, the group pivoted in mid-2022 to RomCom..."
Exploited software
MITRE ATT&CK
Reporting
BianLian emerged as a Go-based ransomware family targeting organizations in manufacturing, education, healthcare, and BFSI, with victims reporting file encryption and double-extortion threats. The malware appends the .bianlian extension to encrypted files, drops a ransom note named "Look at this instruction.txt", and warns that allegedly stolen financial, client, business, technical, and personal data will be leaked within ten days unless payment is made through negotiations conducted over TOX Messenger and a Tor-based leak site. Technical analysis shows the malware was built to hinder detection and speed impact on victim systems. BianLian performs anti-analysis checks associated with MITRE ATT&CK T1497 virtualization and sandbox evasion, creates multiple threads to accelerate encryption, enumerates drives from A: through Z:, excludes selected files and folders from encryption, and deletes itself after execution. Its behavior also aligns with broader defense-evasion patterns such as executable obfuscation and packing captured in MITRE ATT&CK T1027.002, underscoring how the ransomware combines rapid file encryption with techniques intended to frustrate automated analysis and reverse engineering.
Check Point Research reported that a newer Smokeloader variant introduced multiple changes to improve stealth, evasion, and persistence. The malware was observed bypassing userland hooks by loading a duplicate copy of ntdll.dll, adding anti-VM and anti-debugging checks, changing its URL decoding routine and network connection structure, and modifying persistence by using startup .lnk files followed by delayed scheduled-task creation. The activity was tied to a broader campaign that targeted trezor.io through FakeDNS redirection and used DDoS plugins while also delivering the Azorult infostealer from fileboard.live. Researchers said C2 naming patterns, reused RC4 keys, and historical overlap with Amadey, AveMaria, and ServHelper campaigns suggest the operator behind this Smokeloader activity may be TA505.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.