logo

Banking Trojans Target Latin America and Europe Through Google Cloud Run

ID: 2acb02d7-151f-5959-ad60-5999fc4b32e8

STIX ID: report--2acb02d7-151f-5959-ad60-5999fc4b32e8

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-02-26

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Researchers report a surge in high-volume phishing campaigns that weaponize Google Cloud Run and other cloud services to host and distribute banking trojans (Astaroth, Mekotio, Ousaban) and various info-stealers; attackers use malicious MSI droppers, cloud storage redirects, geofencing, QR-code lures, open redirects, and compromised email services (e.g., SendGrid) with phishing-as-a-service kits to target organizations across LATAM, Europe and specific sectors such as oil & gas.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.