AllaKore RAT Malware Targeting Mexican Firms with Financial Fraud Tricks
ID: 066a9381-add5-5a34-b0a1-ad205103ac72
STIX ID: report--066a9381-add5-5a34-b0a1-ad205103ac72
Feed Name: The Hacker News
A persistent, financially motivated spear-phishing campaign (active since at least 2021) targets large Mexican companies and financial/cryptocurrency platforms by delivering a modified AllaKore RAT via ZIP/MSI installers that verify Mexican geolocation; the RAT was enhanced to steal banking credentials, capture clipboard content, provide reverse shell access, and execute additional payloads. The report also notes unrelated research identifying three vulnerabilities (CVE-2024-0175/76/77) in Lamassu Douro bitcoin ATMs that previously allowed local attackers to execute arbitrary code via the update/QR mechanisms and have since been patched.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
