Cuba Ransomware partners with Hancitor for spam-fueled attacks : vimarsana.com

Cuba Ransomware partners with Hancitor for spam-fueled attacks


Cuba Ransomware partners with Hancitor for spam-fueled attacks
By
05:00 AM
The Cuba Ransomware gang has teamed up with the spam operators of the Hancitor malware to gain easier access to compromised corporate networks.
The Hancitor (Chancitor) downloader has been in operation since 2016 when Zscaler saw it distributing the Vawtrak information-stealing Trojan. Since then, numerous campaigns have been seen over the years where Hancitor installs password-stealers, such as Pony, Ficker, and more recently, Cobalt Strike.
Hancitor is usually distributed through malicious spam campaigns pretending to be DocuSign invoices, as shown below.
Fake DocuSign spam pushing Hancitor
When a recipient clicks on the 'Sign document' link, they will download a malicious Word document that tries to convince the target to disable protections.

Related Keywords

Cuba , Russia , Russian , Hancitor Malwaretraffic , Hancitor Chancitor , Fidel Castro , , Fake Docusign , Cuba Ransomware , Malicious Word , Cobalt Strike , Remote Desktop , கியூபா , ரஷ்யா , ரஷ்ய , பிடல் காஸ்ட்ரோ , கோபால்ட் வேலைநிறுத்தம் , தொலைநிலை டெஸ்க்டாப் ,

© 2024 Vimarsana