Hancitor Making Use of Cookies to Prevent URL Scraping
ID: 81c5efd2-98a6-5638-b7a1-9d8bfb4e2908
STIX ID: report--81c5efd2-98a6-5638-b7a1-9d8bfb4e2908
Feed Name: McAfee Labs Blog
This McAfee blog details an active Hancitor malspam campaign that lures victims with fake DocuSign links, uses Google feedproxy redirects and JavaScript cookie checks to evade crawlers, and delivers macro-enabled documents which download a Hancitor DLL executed via rundll32. Post-compromise behavior includes C2 communication, deployment of Cobalt Strike beacons, spam modules to spread further, and delivery of stealers and ransomware; the report includes specific IOCs and MITRE mappings for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
