logo

New Coyote Trojan Targets 61 Brazilian Banks with Nim-Powered Attack

ID: 5c218f7c-aa0c-5ee4-bc09-aaab18885f64

STIX ID: report--5c218f7c-aa0c-5ee4-bc09-aaab18885f64

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-02-09

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Coyote is a sophisticated multi-stage banking trojan observed targeting 61 Brazilian banks that leverages the Squirrel installer to deploy an Electron/Node.js application which executes a Nim-based loader and DLL side-loading (malicious libcef.dll via obs-browser-page.exe). The malware monitors for banking apps/websites and supports overlays, keystroke logging, screenshots, process termination, mouse control, fake update screens and remote command execution; Kaspersky documented the campaign and noted a shift from Delphi to Nim. The report also mentions a separate Python-based info stealer and recent Brazilian law-enforcement actions against banking-malware operators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.