Experten warnen vor Mekotio-Bankentrojaner, der auf lateinamerikanische Länder abzielt

Teilen:

Financial institutions in Latin America are being threatened by a banking trojan called Mekotio (aka Melcoz).

That’s according to findings from Trend Micro, which said it recently observed a surge in cyber attacks distributing the Windows malware.

Mekotio, known to be actively put to use since 2015, is known to target Latin American countries like Brazil, Chile, Mexico, Spain, Peru, and Portugal with an aim to steal banking credentials.

First documented by ESET in August 2020, it’s part of a tetrade of banking trojans targeting the region, such as Guildma, Javali, and Grandoreiro, the latter of which was dismantled by law enforcement earlier this year.

Cybersecurity
“Mekotio shares common characteristics for this type of malware, such as being written in Delphi, using fake pop-up windows, containing backdoor functionality and targeting Spanish- and Portuguese-speaking countries,” the Slovakian cybersecurity firm said at the time.

The malware operation suffered a blow in July 2021 when Spanish law enforcement agencies arrested 16 individuals belonging to a criminal network in connection with orchestrating social engineering campaigns targeting European users that delivered Grandoreiro and Mekotio.

Attack chains involve the use of tax-themed phishing emails that aim to trick recipients into opening malicious attachments or clicking on bogus links that lead to the deployment of an MSI installer file, which, in turn, makes use of an AutoHotKey (AHK) script to launch the malware.

sc
The Red Mongoose Daemon Infection Chain
It’s worth noting that the infection process marks a slight deviation from the one previously detailed by Check Point in November 2021, which made use of an obfuscated batch script that runs a PowerShell script to download a second-stage ZIP file containing the AHK script.

Once installed, Mekotio harvests system information and establishes contact with a command-and-control (C2) server to receive further instructions.

Its main objective is to siphon banking credentials by displaying fake pop-ups that impersonate legitimate banking sites. It can also capture screenshots, log keystrokes, steal clipboard data, and establish persistence on the host using scheduled tasks.

Cybersecurity
The stolen information can then be used by the threat actors to gain unauthorized access to users’ bank accounts and perform fraudulent transactions.

“The Mekotio banking trojan is a persistent and evolving threat to financial systems, especially in Latin American countries,” Trend Micro said. “It uses phishing emails to infiltrate systems, with the goal of stealing sensitive information while also maintaining a strong foothold on compromised machines.”

The development comes as Mexican cybersecurity firm Scitum disclosed details of a new Latin American banking trojan codenamed Red Mongoose Daemon that, similar to Mekotio, utilizes MSI droppers distributed via phishing emails masquerading as invoices and tax notes.

“The main objective of Red Mongoose Daemon is to steal victims’ banking information by spoofing PIX transactions through overlapping windows,” the company said. “This trojan is aimed at Brazilian end users and employees of organizations with banking information.”

“Red Mongoose Daemon has capabilities for manipulating and creating windows, executing commands, controlling the computer remotely, manipulating web browsers, hijacking clipboards, and impersonating Bitcoin wallets by replacing copied wallets with the ones used by cybercriminals.”

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
9:58 am, Feb. 1, 2025
Wetter-Symbol 5°C
L: 4° | H: 6°
overcast clouds
Luftfeuchtigkeit: 87 %
Druck: 1030 mb
Wind: 6 mph ESE
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 7:38 am
Sonnenuntergang: 4:49 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
4° | 6°°C 0 mm 0% 6 mph 85 % 1030 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
2° | 7°°C 0 mm 0% 6 mph 84 % 1025 mb 0 mm/h
Mo. Feb. 03 9:00 pm
Wetter-Symbol
2° | 9°°C 0 mm 0% 5 mph 85 % 1026 mb 0 mm/h
Di. Feb. 04 9:00 pm
Wetter-Symbol
4° | 9°°C 1 mm 100% 12 mph 93 % 1026 mb 0 mm/h
Mi. Feb. 05 9:00 pm
Wetter-Symbol
4° | 8°°C 0.8 mm 80% 9 mph 91 % 1046 mb 0 mm/h
Today 12:00 pm
Wetter-Symbol
5° | 6°°C 0 mm 0% 6 mph 82 % 1030 mb 0 mm/h
Today 3:00 pm
Wetter-Symbol
6° | 6°°C 0 mm 0% 6 mph 75 % 1029 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
5° | 5°°C 0 mm 0% 6 mph 79 % 1027 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
3° | 3°°C 0 mm 0% 4 mph 85 % 1026 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
3° | 3°°C 0 mm 0% 5 mph 84 % 1024 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
2° | 2°°C 0 mm 0% 4 mph 83 % 1023 mb 0 mm/h
Tomorrow 6:00 am
Wetter-Symbol
2° | 2°°C 0 mm 0% 4 mph 82 % 1022 mb 0 mm/h
Tomorrow 9:00 am
Wetter-Symbol
3° | 3°°C 0 mm 0% 4 mph 77 % 1022 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€97,994.51
-2.64%
Ethereum(ETH)
€3,125.45
-0.83%
XRP(XRP)
€2.87
-3.46%
Fesseln(USDT)
€0.97
-0.02%
Solana(SOL)
€219.64
-3.41%
USDC(USDC)
€0.97
0.01%
Dogecoin(DOGE)
€0.310625
-1.88%
Shiba Inu(SHIB)
€0.000018
-0.19%
Pepe(PEPE)
€0.000013
1.78%
Nach oben scrollen