HomeSecurityCoyote Banking Trojan executes malicious scripts via Windows LNK

Coyote Banking Trojan executes malicious scripts via Windows LNK

A new wave of cyberattacks, leveraging the Coyote Banking Trojan, has been detected targeting financial institutions in Brazil.

See also: Brazil: Phishing emails distribute banking trojan Astaroth

Coyote Banking Trojan

This sophisticated malware uses malicious Windows LNK files as an entry point to execute PowerShell scripts, enabling multi-stage infection chains that result in data theft and system compromise.

The Coyote Banking Trojan attack begins with a malicious LNK file that executes a secret PowerShell. This command connects to a remote server to download additional payloads.

Fortinet researchers noted that this script initiates the download of encrypted shellcode, which is decoded and executed to load the next stage of the attack.

See also: ErrorFather: Campaign distributes variant of banking Trojan Cerberus

The malware offers many capabilities such as keystroke logging and screenshot capture, displaying phishing that mimic banking interfaces, terminating processes and shutting down systems, and blocking user access with misleading messages such as “Working on updates.”

Coyote Banking Trojan executes malicious scripts via Windows LNK

The Coyote Banking Trojan uses modern programming tools such as Nim and Node.js, enhancing its stealth and sophistication. It has targeted over 70 Brazilian financial institutions and platforms .

It monitors active windows for specific banking applications or websites, initiating malicious actions when detected.

See also: Gh0st RAT Trojan: Targets Chinese Windows Users via Fake Chrome Site

To protect against Banking Trojans like Coyote, it is crucial to implement a combination of preventative measures and reliable software solutions. Make sure your operating system and applications are always updated to the latest versions to address security vulnerabilities. Use strong, unique passwords for your online banking accounts and enable multi-factor authentication whenever possible. Avoid clicking on suspicious links or downloading attachments from unknown sources, as these are common methods for distributing malware. Additionally, install reliable antivirus software with real-time scanning capabilities to detect and block malicious activity. Regularly check your bank statements for any unauthorized transactions and report them to your financial institution immediately .

Source: cybersecuritynews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS