Exposing Coyote: The Next-Gen Banking Trojan Revolutionizing Cyber Threats in Brazil
ID: d924e7a8-0843-5b82-a83b-69d926976035
STIX ID: report--d924e7a8-0843-5b82-a83b-69d926976035
Feed Name: Seqrite Blog
A newly discovered banking trojan called Coyote uses the Squirrel Installer framework to sideload a malicious DLL that loads a .NET/CLR MSIL payload in memory. The payload decrypts AES-obfuscated components, achieves persistence via HKCU\Environment\UserInitMprLogonScript, monitors the foreground window for Brazilian banking applications, and contacts a C2 using an embedded encrypted X.509 certificate; the C2 can issue 25+ actions (screenshots, keylogging, process/registry manipulation, exfiltration). IOCs provided include multiple file hashes and domains associated with the campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
