logo

AllaKore RAT Malware Targeting Mexican Firms with Financial Fraud Tricks

ID: 066a9381-add5-5a34-b0a1-ad205103ac72

STIX ID: report--066a9381-add5-5a34-b0a1-ad205103ac72

Feed Name: The Hacker News

Threat Score
72/100

Date Published: 2024-01-27

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

A persistent, financially motivated spear-phishing campaign (active since at least 2021) targets large Mexican companies and financial/cryptocurrency platforms by delivering a modified AllaKore RAT via ZIP/MSI installers that verify Mexican geolocation; the RAT was enhanced to steal banking credentials, capture clipboard content, provide reverse shell access, and execute additional payloads. The report also notes unrelated research identifying three vulnerabilities (CVE-2024-0175/76/77) in Lamassu Douro bitcoin ATMs that previously allowed local attackers to execute arbitrary code via the update/QR mechanisms and have since been patched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.