logo

Cybercriminals Targeting Latin America with Sophisticated Phishing Scheme

ID: e2ab8ce4-1659-5dcc-9a0c-f79c6fdf9d2f

STIX ID: report--e2ab8ce4-1659-5dcc-9a0c-f79c6fdf9d2f

Feed Name: The Hacker News

Threat Score
65/100

Date Published: 2024-04-08

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

A phishing and malvertising campaign focused on Latin America delivers malicious ZIP attachments that extract to HTML lures; these lever geofencing and Cloudflare Turnstile CAPTCHAs to redirect victims to RAR archives containing PowerShell scripts that fingerprint systems, check for AV, and retrieve additional malware (RATs, stealers, and miners) from cloud storage. Researchers note overlaps with prior Horabot activity and emphasize the attackers' use of geo-restricted domains, newly created infrastructure, and malvertising to evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.