Coyote: A multi-stage banking Trojan abusing the Squirrel installer
ID: 853f0a42-48f8-5104-ae80-5b90a924936a
STIX ID: report--853f0a42-48f8-5104-ae80-5b90a924936a
Feed Name: Securelist by Kaspersky
Threat Score
Kaspersky researchers describe "Coyote", a sophisticated Brazilian banking Trojan that uses a malicious Squirrel installer, an Electron/NodeJS loader and a Nim-based loader to unpack and run a .NET banker in memory; it achieves persistence via logon script registry keys, communicates with C2 via mutual TLS, supports overlays, keylogging, screenshots and remote commands, and includes IoCs and telemetry showing most infections originate in Brazil.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
