Remove 12
article thumbnail

Connecting the Bots – Hancitor fuels Cuba Ransomware Operations

Security Affairs

It is known since at least 2016 for dropping Pony and Vawtrak. Files are encrypted using ChaCha20 with 12-bytes length IV. The Cuba Ransomware gang has partnered with the crooks behind the Hancitor malware in attacks aimed at corporate networks. The Hancitor downloader has been around for quite some time already.