{"id":61816,"date":"2018-02-07T10:00:24","date_gmt":"2018-02-07T18:00:24","guid":{"rendered":"https:\/\/www.paloaltonetworks.com\/blog\/?p=61816"},"modified":"2026-06-11T15:27:18","modified_gmt":"2026-06-11T22:27:18","slug":"threat-brief-hancitor-actors","status":"publish","type":"post","link":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/2018\/02\/threat-brief-hancitor-actors\/","title":{"rendered":"Threat Brief: Hancitor Actors"},"content":{"rendered":"<p>If you need to understand one thing about cybercrime, it\u2019s that it is all about business.<\/p>\n<p>In our latest Unit 42 research on cybercriminals using the Hancitor malware, we show that not only are their attacks about business, we can see these cybercriminals deftly applying some fundamental business principles around timing, specialization, and globalization.<\/p>\n<p>Hancitor is a malware that focuses getting other malware onto the victim\u2019s system. In the case of Hancitor, it\u2019s typically banking Trojans that steal the victim\u2019s banking information.<\/p>\n<p>In our latest research, we can see the attackers behind Hancitor have been timing their attacks to happen during the busiest time of the global working week, the middle of the week. And we\u2019ve seen that in adapting their attacks to better evade detection, they\u2019ve specialized their operations around the globe.<\/p>\n<p>Hancitor isn\u2019t particularly advanced in its tactics: it\u2019s ideal target is an old or outdated version of Microsoft Windows like Windows 7 or even Windows XP. But it\u2019s effective enough that when used in several hundred different spam campaigns every month it pays for the criminals to keep up these attacks against targets around the world.<\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-size: 18pt;\">Timing <\/span><\/p>\n<p>In our most recent research, one of the things that jumped out for our researchers is the clear pattern around the timing of the attacks. As you can see in Figure 1 below, throughout 2017, the Hancitor attacks show clear spikes in their occurrence and these spikes happen during the middle of the week.<\/p>\n<p><div style=\"max-width:100%\" data-width=\"600\"><span class=\"ar-custom\" style=\"padding-bottom:29%;\"><img loading=\"lazy\" decoding=\"async\"  class=\"aligncenter wp-image-61300 lozad\"  data-src=\"https:\/\/www.paloaltonetworks.com\/blog\/wp-content\/uploads\/2018\/02\/Hancitor_1.png\" alt=\"Hancitor_1\" width=\"600\" height=\"174\" \/><\/span><\/div><\/p>\n<p style=\"text-align: center;\"><em>Figure 1: Timeline of Hancitor campaign activity since January 2017.<\/em><\/p>\n<p>The attackers behind Hancitor aren\u2019t the first to time their spam attacks like this, but it is an effective tactic to try and increase their chances of success, especially when combined with the other innovation that we\u2019ve seen.<\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-size: 18pt;\">Adapting the Attacks<\/span><\/p>\n<p>In the past, Hancitor was sent as a malicious attachment in a spam email which would then download and install the attackers\u2019 final malware like a banking Trojan. When they would do this, the Hancitor attachment would download and install the final malware from a malicious or compromised site.<\/p>\n<p>But as organizations have gotten more effective at blocking malicious attachments like Hancitor, we\u2019ve seen the attackers behind Hancitor adapt to evade detection and prevention.<\/p>\n<p>They\u2019ve done this by moving the Hancitor malware from being a malicious attachment in spam to itself being a malicious download. The spam the attackers use no long has a malicious attachment but instead a malicious link that downloads the malicious Hancitor attachment.<\/p>\n<p>To do this, they make the spam look like something that requires you to click and download something like and invoice, a message, or a delivery notification. Figure 2 shows one of these that was made to look like an Amazon shipping notice.<\/p>\n<p><div style=\"max-width:100%\" data-width=\"600\"><span class=\"ar-custom\" style=\"padding-bottom:42.33%;\"><img loading=\"lazy\" decoding=\"async\"  class=\"aligncenter wp-image-61417 lozad\"  data-src=\"https:\/\/www.paloaltonetworks.com\/blog\/wp-content\/uploads\/2018\/02\/Hancitor_4.png\" alt=\"Hancitor_4\" width=\"600\" height=\"254\" \/><\/span><\/div><\/p>\n<p style=\"text-align: center;\"><em>Figure 2: Hancitor malspam example from February 2017.<\/em><\/p>\n<p>This means that a Hancitor attack now has two downloads rather than one and what these attackers did around the malicious downloads shows another modern business tactic: globalization.<\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-size: 18pt;\">Globalizing the Attacks<\/span><\/p>\n<p>Figure 3 below is a map showing where our Unit 42 researchers have found webistes involved in Hancitor attacks.<\/p>\n<p><div style=\"max-width:100%\" data-width=\"600\"><span class=\"ar-custom\" style=\"padding-bottom:54.17%;\"><img loading=\"lazy\" decoding=\"async\"  class=\"aligncenter wp-image-61534 lozad\"  data-src=\"https:\/\/www.paloaltonetworks.com\/blog\/wp-content\/uploads\/2018\/02\/Hancitor_7.png\" alt=\"Hancitor_7\" width=\"600\" height=\"325\" \/><\/span><\/div><\/p>\n<p style=\"text-align: center;\"><em>Figure 3: Hancitor distribution servers globally thus far in 2017<\/em><\/p>\n<table align=\"center\">\n<tbody>\n<tr>\n<td width=\"159\">Country<\/td>\n<td width=\"180\">Number of Distribution servers<\/td>\n<\/tr>\n<tr>\n<td width=\"159\">United States<\/td>\n<td width=\"180\">197<\/td>\n<\/tr>\n<tr>\n<td width=\"159\">Japan<\/td>\n<td width=\"180\">23<\/td>\n<\/tr>\n<tr>\n<td width=\"159\">Vietnam<\/td>\n<td width=\"180\">13<\/td>\n<\/tr>\n<tr>\n<td width=\"159\">Singapore<\/td>\n<td width=\"180\">12<\/td>\n<\/tr>\n<tr>\n<td width=\"159\">Russia<\/td>\n<td width=\"180\">7<\/td>\n<\/tr>\n<tr>\n<td width=\"159\">Brazil<\/td>\n<td width=\"180\">6<\/td>\n<\/tr>\n<tr>\n<td width=\"159\">Malaysia<\/td>\n<td width=\"180\">6<\/td>\n<\/tr>\n<tr>\n<td width=\"159\">Hong Kong<\/td>\n<td width=\"180\">5<\/td>\n<\/tr>\n<tr>\n<td width=\"159\">South Africa<\/td>\n<td width=\"180\">4<\/td>\n<\/tr>\n<tr>\n<td width=\"159\">Thailand<\/td>\n<td width=\"180\">4<\/td>\n<\/tr>\n<tr>\n<td width=\"159\">India<\/td>\n<td width=\"180\">2<\/td>\n<\/tr>\n<tr>\n<td width=\"159\">Ireland<\/td>\n<td width=\"180\">2<\/td>\n<\/tr>\n<tr>\n<td width=\"159\">Kazakhstan<\/td>\n<td width=\"180\">2<\/td>\n<\/tr>\n<tr>\n<td width=\"159\">Taiwan<\/td>\n<td width=\"180\">2<\/td>\n<\/tr>\n<tr>\n<td width=\"159\">Turkey<\/td>\n<td width=\"180\">2<\/td>\n<\/tr>\n<tr>\n<td width=\"159\">Ukraine<\/td>\n<td width=\"180\">2<\/td>\n<\/tr>\n<tr>\n<td width=\"159\">Argentina<\/td>\n<td width=\"180\">1<\/td>\n<\/tr>\n<tr>\n<td width=\"159\">Canada<\/td>\n<td width=\"180\">1<\/td>\n<\/tr>\n<tr>\n<td width=\"159\">Germany<\/td>\n<td width=\"180\">1<\/td>\n<\/tr>\n<tr>\n<td width=\"159\">Israel<\/td>\n<td width=\"180\">1<\/td>\n<\/tr>\n<tr>\n<td width=\"159\">Italy<\/td>\n<td width=\"180\">1<\/td>\n<\/tr>\n<tr>\n<td width=\"159\">Netherlands<\/td>\n<td width=\"180\">1<\/td>\n<\/tr>\n<tr>\n<td width=\"159\">Republic of Korea<\/td>\n<td width=\"180\">1<\/td>\n<\/tr>\n<tr>\n<td width=\"159\">Republic of Lithuania<\/td>\n<td width=\"180\">1<\/td>\n<\/tr>\n<tr>\n<td width=\"159\">United Kingdom<\/td>\n<td width=\"180\">1<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: center;\"><em>Table 1 \u2013 Number of Distribution Servers by Country<\/em><\/p>\n<p>&nbsp;<\/p>\n<p>The hot spots in the United States represents distribution servers which are created using fraud based accounts at various hosting providers that are hosting the Hancitor documents while the hotspots in Asia represent legitimate sites for small and medium businesses that have been compromised by the actors behind Hancitor campaign to host the malicious Hancitor documents.<\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-size: 18pt;\">Conclusion<\/span><\/p>\n<p>Attackers are always making business decisions to optimize their attacks in ways that are most successful and profitable. What is most interesting about Hancitor is the way these decisions so clearly reflect an awareness of business realities (by targeting peak working times) and dividing up the \u201cwork\u201d of their attacks in a way that so clearly mirrors mainstream business decisions around globalizing operations.<\/p>\n<p>In the end, while Hancitor may not be sophisticated, these steps to adapt and stay effective seem to be succeeding. And we expect to continue to see Hancitor be a global threat for the foreseeable future.<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Read this Threat Brief to learn how Hancitor threat actors use fundamental business tactics to deliver attacks <\/p>\n","protected":false},"author":287,"featured_media":25785,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[10737],"tags":[1302,5410,2506],"coauthors":[3069],"class_list":["post-61816","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-threat-intelligence","tag-cybercrime","tag-cybercrime-business","tag-hancitor"],"jetpack_featured_media_url":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-content\/uploads\/2017\/03\/Linkedin.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/61816","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/users\/287"}],"replies":[{"embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/comments?post=61816"}],"version-history":[{"count":3,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/61816\/revisions"}],"predecessor-version":[{"id":61828,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/61816\/revisions\/61828"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/media\/25785"}],"wp:attachment":[{"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/media?parent=61816"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/categories?post=61816"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/tags?post=61816"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/origin-researchcenter.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/coauthors?post=61816"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}