logo

Experts Warn of Mekotio Banking Trojan Targeting Latin American Countries

ID: 9d5da618-7589-577c-ba02-6ae9380f512f

STIX ID: report--9d5da618-7589-577c-ba02-6ae9380f512f

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-07-08

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

Trend Micro reported a surge in Mekotio (Melcoz) banking-trojan activity targeting Latin American countries (Brazil, Chile, Mexico, Spain, Peru, Portugal) where attackers use tax-themed phishing to deliver MSI droppers that deploy AutoHotKey scripts; Mekotio harvests system info, contacts C2 servers and steals banking credentials via fake pop-ups while also logging keystrokes, taking screenshots, hijacking clipboards and maintaining persistence. Mexican firm Scitum disclosed a similar threat named Red Mongoose Daemon focused on Brazilian users, which also uses overlapping windows to spoof transactions and replaces copied cryptocurrency wallets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.