HomeSecurityPhishing emails distribute Horabot malware in Latin America

Phishing emails distribute Horabot malware in Latin America

A new targeted phishing campaign is targeting Latin American countries , distributing the Horabot malware . According to Fortinet, the phishing emails contain fake invoices or financial documents and target Spanish-speaking Windows users in regions such as Mexico, Colombia, Chile, Peru, Guatemala, and Argentina.

Phishing emails distribute Horabot malware in Latin America

As explains , the messages used in the campaign contain malicious attachments, which allow cybercriminals to steal email credentials, harvest contacts, and install banking trojans.

See also: New phishing attack abuses Blob URIs to bypass SEG

The attacks, observed by Fortinet in April 2025, send messages from victims' mailboxes using Outlook COM automation and effectively spread the malware within corporate or personal networks.

Attackers also use VBScript, AutoIt, and PowerShell scripts for system reconnaissance, credential theft, and installation of additional malicious components.

Horabot is not a new malware. It was reported by Cisco Talos in June 2023, but it had been launching attacks since 2020, targeting Spanish-speaking users in Latin America. The attacks are believed to have been carried out by a hacking group based in Brazil. Furthermore, in 2024, Trustwave SpiderLabs uncovered a similar phishing campaign in the same region, which bore strong similarities to Horabot’s actions, confirming the ongoing threat to users in the region.

New phishing techniques: How the Horabot threat works

According to Fortinet, the new phishing attacks start with deceptive emails that appear to be invoices and invite recipients to open an attached ZIP file. Users believe that an innocent PDF file, but in reality there is an HTML file with Base64-encoded HTML data. This triggers communication with an external server and downloads a second ZIP file with new malicious content.

This new file contains an HTA (HTML Application), which "loads" a script from a remote server. The script inserts a VBScript that performs security checks: if it detects Avast antivirus installed or if it finds that it is running in a virtual machine, it stops it from running to avoid detection.

See also: CoGUI: New phishing kit has targeted millions of users

If not blocked, the script proceeds to information system and send it to a control server. At the same time, it activates additional payloads: an AutoIt script that releases a banking trojan via DLL and a PowerShell script that scans Outlook for email addresses and spreads new phishing messages within the network.

The attack doesn't stop there. As Cara Lin of FortiGuard Labs explains, the Horabot malware continues by stealing credentials from popular browsers, including Chrome, Edge, Opera, Brave, and others, removing saved login data and history. In addition, the software monitors user activity and can display fake pop-ups designed to steal banking or other sensitive account credentials.

Latin America phishing emails Horabot malware
Phishing emails distribute Horabot malware in Latin America

Phishing protection

Phishing attacks can be very effective, but you can protect yourself by following these basic tips:

Be wary of suspicious emails and messages

  • Do not click on links or download attachments from unknown or unexpected senders.
  • Check carefully email address —phishers often use similar-looking addresses.
  • Look for spelling and grammatical errors, which are common in phishing emails.

Verify before you act

  • If an email requires immediate action (like “Your account will be locked!”), verify directly by visiting the official website instead of clicking on links.
  • Contact the sender through official channels (if you are unsure).

Hover over links (before clicking)

  • Hover over links to see the actual URL before clicking. If it looks strange or different from the official domain, don't click.

Enable multi-factor authentication (MFA)

  • Even if a hacker gets password , MFA adds an extra layer of security (like a code sent to your phone).

Keep software and security tools up to date

  • Regularly update your browser, operating system, and antivirus software to protect against malware (e.g. Horabot).

See also: Darcula phishing: Thousands of credit cards stolen

Don't share sensitive information via email

  • Legitimate companies will not ask for passwords, social security numbers, or banking information via email.

Educate yourself and your team

  • Stay up to date on the latest phishing tactics and train employees or family members on how to spot them.

Use a Password Manager

  • Password managers help create and store strong, unique passwords for each website, reducing the risk of a breach.

Report Phishing Attempts

  • If you receive a phishing message, report it to your email provider and the company being impersonated.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS