logo

Coyote: A multi-stage banking Trojan abusing the Squirrel installer

ID: 853f0a42-48f8-5104-ae80-5b90a924936a

STIX ID: report--853f0a42-48f8-5104-ae80-5b90a924936a

Feed Name: Securelist by Kaspersky

Threat Score
78/100

Date Published: 2024-02-08

Date Updated: 2026-04-29

Author: GReAT

...
...

Kaspersky researchers describe "Coyote", a sophisticated Brazilian banking Trojan that uses a malicious Squirrel installer, an Electron/NodeJS loader and a Nim-based loader to unpack and run a .NET banker in memory; it achieves persistence via logon script registry keys, communicates with C2 via mutual TLS, supports overlays, keylogging, screenshots and remote commands, and includes IoCs and telemetry showing most infections originate in Brazil.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.