TA511 is a financially motivated cybercriminal threat actor best known for operating Hancitor, also referred to as Chanitor, and tracked under aliases including MAN1 and Moskalvzapoe. The group has been a prolific distributor of malware through large-scale phishing campaigns, typically using invoice, delivery, or document-signing themes to induce victims to open malicious attachments or follow links to weaponized documents. Hancitor has functioned primarily as an initial-access and malware delivery platform on Windows systems, commonly delivered through malicious Office documents and, in some campaigns, Excel add-ins. Infection chains have relied on social engineering and user-enabled macro or add-in execution, after which Hancitor establishes command-and-control communications and retrieves additional payloads. TA511 has repeatedly used Hancitor to deliver follow-on malware including Ficker Stealer, Cobalt Strike, NetSupport Manager RAT, Send-Safe spambot malware, and network reconnaissance tooling. In enterprise environments, especially those joined to Active Directory domains, Hancitor activity has been associated with rapid deployment of Cobalt Strike for post-compromise operations. Observed behaviors support capabilities spanning initial access, credential theft through delivered stealers, reconnaissance, lateral-enablement and post-exploitation via Cobalt Strike, exfiltration by secondary payloads, and persistence through malware staging and execution chains. The actor has also used phishing infrastructure that impersonates legitimate brands and services, including document-signing workflows, to improve lure credibility. TA511 has historical links to other banking malware ecosystems. The actor was one of the most prevalent users of the original ZLoader strain and later shifted to Panda Banker around late 2017. Hancitor campaigns attributed to TA511 remained active into 2021 and were notable for consistent delivery patterns and recurring use of secondary payloads aligned with credential theft, access monetization, and further criminal operations. TA511 is widely regarded as an e-crime operator rather than a state-sponsored intrusion set.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
48 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with malspam campaigns delivering Hancitor, including DocuSign-themed phishing emails using Google feedproxy URLs that led to malicious XLL or Word document payloads.
Distributes Hancitor via email campaigns using Google Drive links and malicious Word documents with macros, then uses Hancitor for initial access and delivery of follow-on malware including Ficker Stealer, Cobalt Strike, Send-Safe spambot malware, a network ping tool, and NetSupport Manager RAT.
Previously one of the most prevalent threat actors distributing the original ZLoader malware before switching to Panda Banker around November 2017.
Threat group identified as a user of SilentNight and historically associated with Zloader and Panda Banker; discussed as a possible long-term Emotet customer.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.