logo

The SOC Files: Time to “Sapecar”. Unpacking a new Horabot campaign in Mexico

ID: 4f6c9aa7-676c-5116-bae5-73d34c321bfc

STIX ID: report--4f6c9aa7-676c-5116-bae5-73d34c321bfc

Feed Name: Securelist by Kaspersky

Threat Score
78/100

Date Published: 2026-03-18

Date Updated: 2026-04-29

Author: Domenico Caldarella, Mateus Salgado

...
...

This report analyzes an active Horabot criminal campaign that uses social-engineered fake CAPTCHA pages to execute polymorphic HTA/VBScript loaders, an AutoIt-based loader that decrypts and loads an in-memory Delphi banking Trojan (Casbaneiro family), and a PowerShell email spreader to harvest and mass-mail victims; it includes detailed reverse engineering of obfuscation and custom C2 protocols, evidence of thousands of victims (predominantly in Mexico), and ready-to-use detection artifacts (YARA, Suricata, hunting queries).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.