Keep your eyes on these

VERY IMPORTANT

Security Articles

RSS

Hancitor's Use of Cobalt Strike and a Noisy Network Ping Tool

released on 2021-04-02 @ 09:44:20 PM
Hancitor is an information stealer and malware downloader used by a threat actor designated as MAN1, Moskalvzapoe or TA511. Hancitor has evolved to use tools like Cobalt Strike. In recent months, this actor began using a network ping tool to help enumerate the Active Directory (AD) environment of infected hosts. This blog illustrates how the threat actor behind Hancitor uses the network ping tool, so security professionals can better identify and block its use.