logo

Banking Trojan Coyote Abuses Windows UI Automation

ID: 5d0c853f-8dd2-591d-951e-586983b1ad64

STIX ID: report--5d0c853f-8dd2-591d-951e-586983b1ad64

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-07-23

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Coyote, a banking Trojan active since February 2024 in Latin America, has evolved to abuse the Windows UI Automation framework to stealthily harvest credentials and other system information from infected Windows hosts. The malware typically gains access via phishing ZIPs containing malicious .LNK shortcuts that execute PowerShell to deploy payloads, then uses UIA and other techniques (keystroke logging, screenshots, phishing overlays) to target users of dozens of banks and crypto exchanges in Brazil, evading conventional detection and highlighting the need for behavior-based defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.