logo

Horabot Banking Trojan Resurfaces in Mexico With Multi-Stage Phishing and Email Worm Tactics

ID: 0d952fa5-49be-5d80-8459-769c3a818abf

STIX ID: report--0d952fa5-49be-5d80-8459-769c3a818abf

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-03-19

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A multi-stage Horabot banking-trojan campaign targets Mexican users using fake CAPTCHA lures that trick victims into running an HTA; the chain fetches obfuscated JS/VBScript, drops AutoIT components that decrypt and load a Delphi banking DLL, and a PowerShell email worm harvests contacts to propagate malicious PDFs — researchers found ~5,384 infected machines (≈93% in Mexico), recovered C2/socket indicators and recommended blocking HTA execution, deploying YARA/Suricata rules, and adding IoCs to blocklists.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.