Horabot Returns in Mexico, Spreading via Phishing and Email Worm Attacks
ID: 40734aa1-4e55-55a5-8b22-7c17fe5a0665
STIX ID: report--40734aa1-4e55-55a5-8b22-7c17fe5a0665
Feed Name: GBHackers
A SOC analysis of an active Horabot campaign shows a sophisticated, multi-stage operation targeting primarily Mexico and broader Latin America: victims are lured to a fake CAPTCHA page that leads to mshta-executed HTA/JS/VBScript loaders which fetch AutoIt components to decrypt and map a Delphi banking trojan (Casbaneiro/Metamorfo/Zusy) into memory; the threat also includes a PowerShell-based Outlook/MAPI email worm that harvests contacts and propagates invoice-themed lures. The report highlights evasion and persistence techniques (server-side polymorphism, AES-192 encrypted blobs, in-memory DLLs, custom XOR framing for C2), suggests multiple detection anchors (mshta usage, VBScript from unusual domains, AutoIt + AES-192, Casbaneiro export patterns, distinctive “##...##” socket frames), and notes operator language clues pointing to Brazilian origins.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
