Horabot Banking Trojan Resurfaces in Mexico With Multi-Stage Phishing and Email Worm Tactics
ID: 0d952fa5-49be-5d80-8459-769c3a818abf
STIX ID: report--0d952fa5-49be-5d80-8459-769c3a818abf
Feed Name: cybersecurityNews.com
A multi-stage Horabot banking-trojan campaign targets Mexican users using fake CAPTCHA lures that trick victims into running an HTA; the chain fetches obfuscated JS/VBScript, drops AutoIT components that decrypt and load a Delphi banking DLL, and a PowerShell email worm harvests contacts to propagate malicious PDFs — researchers found ~5,384 infected machines (≈93% in Mexico), recovered C2/socket indicators and recommended blocking HTA execution, deploying YARA/Suricata rules, and adding IoCs to blocklists.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
