logo

Coyote malware abuses Microsoft's UI Automation to hunt banking creds

ID: 2095bab3-a78b-53ea-a80e-6ca4cedc5cc6

STIX ID: report--2095bab3-a78b-53ea-a80e-6ca4cedc5cc6

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2025-07-24

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Akamai reported an in-the-wild variant of the Coyote banking trojan that is the first observed malware to abuse Windows UI Automation (UIA) to scrape credentials from browser/address bar UI elements; the variant targets Brazilian users and 75 banking and crypto web addresses, uses GetForegroundWindow and UIA to identify targets, exfiltrates credentials to a C2, and aims to drain accounts while evading detection via techniques like the Squirrel installer.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.