New Coyote Trojan Targets 61 Brazilian Banks with Nim-Powered Attack
ID: 5c218f7c-aa0c-5ee4-bc09-aaab18885f64
STIX ID: report--5c218f7c-aa0c-5ee4-bc09-aaab18885f64
Feed Name: The Hacker News
Coyote is a sophisticated multi-stage banking trojan observed targeting 61 Brazilian banks that leverages the Squirrel installer to deploy an Electron/Node.js application which executes a Nim-based loader and DLL side-loading (malicious libcef.dll via obs-browser-page.exe). The malware monitors for banking apps/websites and supports overlays, keystroke logging, screenshots, process termination, mouse control, fake update screens and remote command execution; Kaspersky documented the campaign and noted a shift from Delphi to Nim. The report also mentions a separate Python-based info stealer and recent Brazilian law-enforcement actions against banking-malware operators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
