Sigma Watch is free and independent. If it saves you time, keep it running. ☕ Buy me a coffee
SigmaWatch
Infostealer

Hancitor

Infostealer Needs review 9 detections found
This entry hasn't been reviewed yet. It was auto-detected from the MITRE ATT&CK catalog because it self-identifies as infostealer-type malware, but no one has curated a full summary or double-checked its reference links. Treat the details below as a starting point, not a verified profile.

Also known as: Chanitor, Hancitor

Auto-detected from the MITRE ATT&CK catalog on 2026-09-28 (S0499) - this entry has not been reviewed or curated yet. See the MITRE ATT&CK link below for what's currently known; a proper summary and authoritative eradication references are pending.

Detection & eradication references

Curated links to authoritative sources — MITRE ATT&CK, CISA advisories, law-enforcement takedown announcements, and vendor threat-intel writeups — for removal, remediation, and further technical detail. Sigma Watch does not publish its own removal steps here, since malware behavior and tooling change too fast for a static write-up to stay reliably accurate.

Detection rules

Source Rule Status Updated
snort ET TROJAN Win32/Hancitor Checkin rev 5 2024-08-28
suricata ET MALWARE Tordal/Hancitor/Chanitor Checkin rev 9 2024-05-02
suricata ET MALWARE Win32/Hancitor Checkin rev 3 2024-04-29
suricata ET MALWARE Chanitor Variant .onion Proxy Domain rev 5 2024-04-13
suricata ET MALWARE Suspected Win32/Hancitor Checkin rev 3 2024-04-04
snort ET TROJAN Suspected Win32/Hancitor Checkin rev 2 2022-02-04
snort ET TROJAN Chanitor Variant .onion Proxy Domain rev 2 2019-08-28
snort ET TROJAN Tordal/Hancitor/Chanitor Checkin rev 4 2017-10-18
yara hancitor — —