Infostealer
Hancitor
Infostealer
Needs review
9 detections found
This entry hasn't been reviewed yet. It was auto-detected from the MITRE ATT&CK catalog
because it self-identifies as infostealer-type malware, but no one
has curated a full summary or double-checked its reference links. Treat the details below as a starting point,
not a verified profile.
Also known as: Chanitor, Hancitor
Auto-detected from the MITRE ATT&CK catalog on 2026-09-28 (S0499) - this entry has not been reviewed or curated yet. See the MITRE ATT&CK link below for what's currently known; a proper summary and authoritative eradication references are pending.
Detection & eradication references
Curated links to authoritative sources — MITRE ATT&CK, CISA advisories, law-enforcement takedown announcements, and vendor threat-intel writeups — for removal, remediation, and further technical detail. Sigma Watch does not publish its own removal steps here, since malware behavior and tooling change too fast for a static write-up to stay reliably accurate.
- Hancitor, Software S0499 — MITRE ATT&CK
Detection rules
| Source | Rule | Status | Updated |
|---|---|---|---|
| snort | ET TROJAN Win32/Hancitor Checkin | rev 5 | 2024-08-28 |
| suricata | ET MALWARE Tordal/Hancitor/Chanitor Checkin | rev 9 | 2024-05-02 |
| suricata | ET MALWARE Win32/Hancitor Checkin | rev 3 | 2024-04-29 |
| suricata | ET MALWARE Chanitor Variant .onion Proxy Domain | rev 5 | 2024-04-13 |
| suricata | ET MALWARE Suspected Win32/Hancitor Checkin | rev 3 | 2024-04-04 |
| snort | ET TROJAN Suspected Win32/Hancitor Checkin | rev 2 | 2022-02-04 |
| snort | ET TROJAN Chanitor Variant .onion Proxy Domain | rev 2 | 2019-08-28 |
| snort | ET TROJAN Tordal/Hancitor/Chanitor Checkin | rev 4 | 2017-10-18 |
| yara | hancitor | — | — |