logo

Analysis of Hancitor – When Boring Begets Beacon

ID: aa4bd4be-9490-5985-8610-4cde42e0215e

STIX ID: report--aa4bd4be-9490-5985-8610-4cde42e0215e

Feed Name: Binary Defense Blog

Threat Score
75/100

Date Published: 2025-08-12

Date Updated: 2026-04-27

...
...

Hancitor is a lightweight but fast-acting malware loader used to deliver Cobalt Strike Beacon and other payloads (FickerStealer, Sendsafe), notably leveraged by the Cuba ransomware group; the report details delivery via malicious Word documents, host profiling (BotID, external IP, domain trust), an RC4-encrypted built-in configuration, HTTP-based C2 check-ins and a five-command table that controls downloading, XOR+LZ decompression, and process-hollowing into svchost or the current process. The document includes sample C2 traffic and a Snort rule, outlines payload decryption and injection routines, and provides actionable detection recipes (KQL, CrowdStrike, Suricata) for network and endpoint defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.