Connecting the Bots – Hancitor fuels Cuba Ransomware Operations
Security Affairs
MAY 7, 2021
It is known since at least 2016 for dropping Pony and Vawtrak. Files are encrypted using ChaCha20 with 12-bytes length IV. The Cuba Ransomware gang has partnered with the crooks behind the Hancitor malware in attacks aimed at corporate networks. The Hancitor downloader has been around for quite some time already.
Let's personalize your content