logo

HANCITOR DOC drops via CLIPBOARD

ID: cac5a202-c288-51de-acf8-57e6041db31b

STIX ID: report--cac5a202-c288-51de-acf8-57e6041db31b

Feed Name: McAfee Labs Blog

Threat Score
70/100

Date Published: 2021-12-13

Date Updated: 2026-04-28

Author: McAfee Labs

...
...

McAfee Labs analyzed a Hancitor campaign that uses Docusign-themed phishing to deliver macro-enabled Word documents which leverage a clipboard-based OLE drop (Selection.Copy) to write nested, password-protected documents and ultimately drop and execute a DLL via rundll32; observed payloads include stealers (FickerStealer, Pony), Cobalt Strike and Cuba ransomware, and the report includes MITRE ATT&CK mappings and IOCs (SHA-256 hashes and URL) for detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.