Experts Warn of Mekotio Banking Trojan Targeting Latin American Countries
ID: 9d5da618-7589-577c-ba02-6ae9380f512f
STIX ID: report--9d5da618-7589-577c-ba02-6ae9380f512f
Feed Name: The Hacker News
Trend Micro reported a surge in Mekotio (Melcoz) banking-trojan activity targeting Latin American countries (Brazil, Chile, Mexico, Spain, Peru, Portugal) where attackers use tax-themed phishing to deliver MSI droppers that deploy AutoHotKey scripts; Mekotio harvests system info, contacts C2 servers and steals banking credentials via fake pop-ups while also logging keystrokes, taking screenshots, hijacking clipboards and maintaining persistence. Mexican firm Scitum disclosed a similar threat named Red Mongoose Daemon focused on Brazilian users, which also uses overlapping windows to spoof transactions and replaces copied cryptocurrency wallets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
