HomeSecurityMekotio banking trojan targets users in Latin America

Mekotio banking trojan targets users in Latin America

Many financial institutions in Latin America (and customers ) have been targeted by the Mekotio banking trojan (also known as Melcoz).

Mekotio banking trojan Latin America

Trend Micro has observed an explosion of attacks distributing malware and targeting Windows systems.

The Mekotio banking trojan has been in use since 2015. It targets Latin American countries such as Brazil, Chile, Mexico, Peru, as well as countries such as Spain and Portugal, with the aim of stealing banking credentials. It was first analyzed by ESET in August 2020.

See also: Google Play: Anatsa banking trojan and malicious apps with millions of downloads

According to the Trend Micro report, Mekotio is written in Delphi and has many of the usual characteristics of a banking trojan, such as the use of fake pop-ups and backdoor. It mainly targets Spanish- and Portuguese-speaking countries.

The malicious operation suffered a blow in July 2021, when Spanish law enforcement agencies arrested 16 individuals carrying out social engineering attacks that distributed Mekotio to European users' systems.

“The Mekotio banking trojan is a persistent and evolving threat to financial systems, especially in Latin American countries,” Trend Micro said. “It uses phishing messages to infiltrate systems, aiming to steal sensitive information, while maintaining a strong foothold on compromised machines.”

See also: Android banking trojan Antidot appears as a Google Play update

The attacks begin with phishing emails that use a tax-related topic. Attackers try to trick recipients into opening malicious attachments or clicking fake links that lead to the deployment of an MSI installer file. This, in turn, uses an AutoHotKey (AHK) script to launch the malware.

This infection process is a bit different from what was observed in 2021, which shows that the operators of the Mekotio banking trojan are evolving and improving their techniques.

Once installed, Mekotio collects system information and contacts a command-and-control (C2) server for further instructions.

Its main goal is to steal banking credentials by displaying fake login windows and impersonating legitimate banking websites. It is also equipped with capabilities that allow it to take screenshots, record keystrokes, steal data from the clipboard, and establish persistence.

See also: Grandoreiro banking trojan “returned” more powerful

Mekotio banking trojan targets users in Latin America
Mekotio banking trojan targets users in Latin America

Attackers can use the stolen data to gain unauthorized access to users' bank accounts. They can steal money and make unauthorized transactions.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Protection from banking trojan (e.g. Mekotio)

  • Installing antivirus  software is essential for protecting  your device. These software can identify and remove malware before it can cause damage . 
  • It's important to keep your operating system and applications up to date. Updates often include security fixes that can protect your device from malware.
  • Avoid installing apps from third-party sources. apps have not undergone the same security checks as those in official stores.
  • Pay attention to the permissions apps ask for. If an app asks for access to personal information that doesn't seem necessary, it may be best not to install it.
  • Be wary of phishing messages  that may try to trick you into downloading malware. These messages  may appear to come from legitimate sources, but they often contain links or attachments that can install malware on your device.
  • Finally, it is important to regularly back up your data. This can help restore your information if your device is infected with malware (e.g. Mekotio banking trojan).

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS