logo

Hancitor Making Use of Cookies to Prevent URL Scraping

ID: 81c5efd2-98a6-5638-b7a1-9d8bfb4e2908

STIX ID: report--81c5efd2-98a6-5638-b7a1-9d8bfb4e2908

Feed Name: McAfee Labs Blog

Threat Score
75/100

Date Published: 2021-07-08

Date Updated: 2026-04-28

Author: McAfee Labs

...
...

This McAfee blog details an active Hancitor malspam campaign that lures victims with fake DocuSign links, uses Google feedproxy redirects and JavaScript cookie checks to evade crawlers, and delivers macro-enabled documents which download a Hancitor DLL executed via rundll32. Post-compromise behavior includes C2 communication, deployment of Cobalt Strike beacons, spam modules to spread further, and delivery of stealers and ransomware; the report includes specific IOCs and MITRE mappings for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.