Malware News Hancitor Downloader Abusing APIs, PowerShell Cmds

Ink

Administrator
Thread author
Verified
Jan 8, 2011
22,318
2
55,055
8,379
Hancitor, more difficult to detect.

The downloader is still spread through malicious attachments, and distributing malware designed to steal data, such as Pony and Vawtrak, but researchers said the way that Hancitor’s payload is delivered is different than from previous iterations.

Two FireEye researchers, Ankit Anubhav and Dileep Kumar Jallepalli, said the downloader has shifted to using a three-pronged delivery approach, and explained the updates in a blog post on Friday.

Full Read - https://www.fireeye.com/blog/threat-research/2016/09/hancitor_aka_chanit.html