Hancitor resurfaced in large email-driven malware campaigns with updated delivery and execution techniques, moving from malicious Word macro attachments to a brief use of RTF files exploiting CVE-2017-11882. Early campaigns used invoice- and billing-themed lures to deliver Word documents whose VB macros decoded embedded shellcode, allocated executable memory through Windows API calls, extracted an encrypted Hancitor payload hidden inside the document, and installed it with persistence as WinHost.exe. Proofpoint also linked Hancitor’s return to a Vawtrak affiliate using botnet IDs 80, 81, and 82, with campaigns primarily targeting U.S. financial organizations and some victims in Canada and the UK.
Researchers reported that Hancitor’s operators repeatedly refreshed the malware’s internals, including a revised command-and-control protocol, in-memory DLL execution, and delivery of additional payloads such as Pony and Vawtrak. In a later campaign, the malware used shellcode and PowerShell launched via the Office Equation Editor flaw to drop a new packer featuring anti-debugging, anti-disassembly, memory-permission changes, and a custom RC4-like unpacking routine before restoring the standard Hancitor payload. Once active, Hancitor collected host details, checked the victim’s external IP through api.ipify.org, and prepared POST requests to multiple gate.php command-and-control endpoints recovered from encrypted configuration data.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
On January 24 and 25, 2018, researchers observed a Hancitor campaign using RTF documents exploiting CVE-2017-11882 instead of the malware family's usual macro-enabled Word documents. The exploit launched shellcode and PowerShell that dropped a PE file containing a new packer before restoring the standard Hancitor payload.
After relative quiet since a major campaign in June 2016, researchers observed a renewed uptick in Hancitor delivery through email-borne Word documents with VB macros. The campaign used invoice, billing, receipt, contract, and overdue-payment lures and generated more than 380,000 observed sessions during the week discussed.
On May 4, the same Vawtrak actor was observed using a new version of the Ruckguv downloader delivered via malicious Word macro documents. The updated Ruckguv downloaded Pony and Vawtrak and changed its payload retrieval and file-writing behavior.
Starting on April 28, a Vawtrak actor associated with botnet IDs 80, 81, and 82 began using an updated Hancitor downloader in malicious Word macro email campaigns. The updated loader downloaded Pony and Vawtrak and introduced changes including a revised C2 protocol and in-memory DLL execution.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 88 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
6 references tracked. Mallory keeps watching after this page renders.
0ffset.net
Open sourceresearchcenter.paloaltonetworks.com
Open sourceresearchcenter.paloaltonetworks.com
Open sourceblog.paloaltonetworks.com
Open sourceproofpoint.com
Open sourceportal.msrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.