Netskope Threat Labs

Hancitor

ATP Sandbox Adv. HeuristicsAVNetskope IPS

Hancitor (a.k.a. Chanitor) is a downloader delivered through malicious spam that installs banking trojans, remote access trojans, and ransomware on infected systems. Its emails carry malicious documents or links, and the downloader fetches payloads from multiple sources to maximize resilience. The family served as a steady first stage for major criminal campaigns for years, and its infrastructure overlaps with other distribution networks that feed the ransomware ecosystem.

First seen
January 2022
Last seen
October 2026
Chanitor

14 techniques across 5 tactics.

TA0001 Initial Access

TA0002 Execution

TA0003 Persistence

  • T1547Boot or Logon Autostart Execution

TA0005 Stealth

TA0011 Command and Control

  • T1105Ingress Tool Transfer
Alert Name
Document-Office.Downloader.Hancitor
Document-Office.Dropper.Hancitor
Document-Office.Trojan.Hancitor
Document-Word.Downloader.Hancitor
Document-Word.Dropper.Hancitor
Document-Word.Trojan.Hancitor
GT:VB.Hancitor.2.48311099
GT:VB.Hancitor.2.69264ADF
GT:VB.Hancitor.2.850BAE5B
GT:VB.Hancitor.2.850BAE5B:EF037