Hancitor, also tracked as Chanitor and associated with TA511/MAN1, remained a persistent Windows malware loader delivered through phishing emails that lured users to malicious Word or Excel documents. The campaign shifted from direct malicious attachments to links hosted on compromised websites, fraudulent hosting accounts, and services such as Google Drive or Google Feed Proxy to evade mail filtering. Once macros were enabled, Hancitor profiled the host, checked external IP information, contacted command-and-control servers over HTTP, and commonly used recurring URI patterns such as /8/forum.php; researchers also documented hard-coded fallback C2 infrastructure and second-stage payloads hosted on compromised business websites.
Intrusions tied to Hancitor showed it functioning as an initial-access malware that frequently delivered Cobalt Strike, Ficker Stealer, Pony, NetSupport Manager RAT, spam bot malware, and other follow-on tools. Incident reports described operators using Hancitor infections for rapid post-exploitation, including network discovery, SMB-based lateral movement, remote service execution, attempted access to lsass.exe, and in one case exploitation of Zerologon (CVE-2020-1472) to reach domain administrator privileges in under an hour. Multiple technical analyses also detailed Hancitor’s layered obfuscation, RC4- and XOR-based decoding, task parsing, and code injection into svchost.exe, underscoring its role as a mature malware delivery platform rather than a standalone payload.

Pull IOCs and campaign context straight into your stack.
17 events from the most recent confirmed update back to the earliest known activity.
Across packet captures from January 20 through March 4, 2021, Unit 42 observed Hancitor infections that performed api.ipify.org checks, used /8/forum.php C2 traffic, and retrieved follow-on payloads including Ficker Stealer and Cobalt Strike.
On 2021-01-12, Hancitor activity resumed after a lull since 2020-12-17, with spoofed DocuSign-themed emails linking to Google Docs pages that generated malicious macro-enabled Word documents. The infection chain dropped Hancitor DLLs and was observed leading to follow-on Cobalt Strike delivery in Active Directory environments.
Unit 42 reported that since November 2020, Hancitor command-and-control URLs had consistently ended with /8/forum.php, providing a recurring network indicator for defenders.
As of December 2017, Hancitor Word documents were most commonly distributed through fraudulent hosting-provider accounts rather than compromised legitimate websites.
By November 2017, Hancitor had reverted from its temporary DDE-based delivery method back to macro-enabled Office documents in malspam campaigns.
Since early October 2017, Hancitor distribution servers were usually set up through fraudulent accounts at hosting providers, marking an infrastructure shift away from relying primarily on compromised servers.
Beginning in early October 2017, Hancitor temporarily shifted to DDE-based Word document delivery before later returning to macro-enabled documents.
From January through September 2017, the majority of compromised domains used for Hancitor infections were located in Asia, suggesting widespread abuse of vulnerable legitimate business servers in the region.
FireEye published research in September 2016 documenting Hancitor, also known as Chanitor, using multiple attack approaches, indicating diversification in the malware's delivery and infection methods.
Palo Alto Networks tested a decoder against 10,000 unique Microsoft Word documents first seen on August 15, 2016 that exhibited Hancitor-like behavior, successfully decoding thousands of stage-1 and stage-2 payloads and identifying only three distinct C2 URLs across the corpus.
Since the end of 2016, Hancitor operators added an extra delivery step by sending links to distribution servers instead of attaching malicious documents directly to emails, a change intended to evade improved email filtering.
A Malwarebytes blog post from November 2015 covered Hancitor activity delivering the Pony trojan via malicious email, showing the malware family was active in malspam campaigns by that time.
ThreatLabZ analyzed Chanitor samples observed since October 2014 and found the downloader using phishing-delivered .scr attachments, api.ipify.org checks, and TOR-to-web C2 beacons to /gate.php before fetching a second-stage payload. In the analyzed case, Chanitor installed a new Vawtrak variant via a dropper that registered the DLL with regsvr32 for persistence.
The DFIR Report states that Hancitor, also known as Chanitor and Tordal, was first observed in 2014.
In July, attackers used a phishing email and malicious Word document to deploy Hancitor, then leveraged Cobalt Strike and a custom Zerologon tool to obtain a domain administrator NTLM hash and compromise key systems within hours.
The DFIR Report documented a Hancitor intrusion in which a malicious macro-enabled Word document delivered Hancitor, which then fetched Ficker Stealer and Cobalt Strike and enabled discovery and lateral movement before defenders interrupted the attack.
A 0ffset reverse-engineering analysis identified a Hancitor sample using build identifier 17bdp12 and stated that this build value indicated a campaign beginning on 17 December.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 176 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
13 references tracked. Mallory keeps watching after this page renders.
zscaler.com
Open sourcemalware-traffic-analysis.net
Open sourcemalware-traffic-analysis.net
Open sourcemalpedia.caad.fkie.fraunhofer.de
Open sourceresearchcenter.paloaltonetworks.com
Open sourcefireeye.com
Open sourceresearchcenter.paloaltonetworks.com
Open sourceblog.malwarebytes.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.