HANCITOR DOC drops via CLIPBOARD
ID: cac5a202-c288-51de-acf8-57e6041db31b
STIX ID: report--cac5a202-c288-51de-acf8-57e6041db31b
Feed Name: McAfee Labs Blog
Threat Score
McAfee Labs analyzed a Hancitor campaign that uses Docusign-themed phishing to deliver macro-enabled Word documents which leverage a clipboard-based OLE drop (Selection.Copy) to write nested, password-protected documents and ultimately drop and execute a DLL via rundll32; observed payloads include stealers (FickerStealer, Pony), Cobalt Strike and Cuba ransomware, and the report includes MITRE ATT&CK mappings and IOCs (SHA-256 hashes and URL) for detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
