Banking Trojan Coyote Abuses Windows UI Automation
ID: 5d0c853f-8dd2-591d-951e-586983b1ad64
STIX ID: report--5d0c853f-8dd2-591d-951e-586983b1ad64
Feed Name: Dark Reading
Coyote, a banking Trojan active since February 2024 in Latin America, has evolved to abuse the Windows UI Automation framework to stealthily harvest credentials and other system information from infected Windows hosts. The malware typically gains access via phishing ZIPs containing malicious .LNK shortcuts that execute PowerShell to deploy payloads, then uses UIA and other techniques (keystroke logging, screenshots, phishing overlays) to target users of dozens of banks and crypto exchanges in Brazil, evading conventional detection and highlighting the need for behavior-based defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
