A new variant of the “Coyote” malware has begun exploiting a Windows accessibility feature, the Microsoft UI Automation (UIA), to detect which banking and cryptocurrency exchange websites a user visits, with the aim of potentially stealing credentials.
See also: Russian hackers use new Authentic Antics malware

Microsoft UIA is a Windows accessibility framework designed to allow assistive technologies to interact with, inspect, and control the user interface (UI) elements of applications
Windows applications expose their UI elements through a “UI Automation tree,” and the UIA API provides the ability to navigate through it, retrieve properties of each element, and interact with them. Akamai researchers had warned as early as December 2024 about the possibility of abusing UIA to steal credentials, noting that this technique bypasses EDR (Endpoint Detection and Response) protection systems.
Now, the same researchers report that they have identified attacks that use this technique «in the real world» since February 2025, marking the first documented case of malware that exploits Microsoft UIA for data theft.
Coyote malware is a banking trojan that attempts to steal credentials from 75 banking and cryptocurrency exchange apps, primarily targeting users in Brazil.
The malware was first recorded in February 2024, using techniques such as keyloggingandphishing window overlays, and has evolved significantly since then.
See also: New LameHug malware uses AI LLM to steal data
According to a report by Akamai, the latest variant of Coyote continues to steal data using traditional methods for applications coded into the malware, but has now added the UIA exploit when the user opens browser-based banking or financial services

If the Coyote malware cannot identify the target from the window title, it uses UIA to extract the URL directly from browser (such as tabs or the address bar). It then compares this address against a predefined list of 75 targeted services.
Some of the banks and exchanges identified through this method are: Banco do Brasil, CaixaBank, Banco Bradesco, Santander, Original bank, Sicredi, Banco do Nordeste, Expanse apps, as well as cryptocurrency platforms such as Binance, Electrum, Bitcoin, Foxbit and others.
Although the exploitation of this accessibility is limited to the target identification stage, Akamai also presented a proof-of-concept demonstration showing how UIA can also be used to intercept credentials typed into these websites.
See also: Hackers distribute Matanbuchus 3.0 malware via Microsoft Teams
Accessibility systems are designed to be robust, enabling people with disabilities to fully utilize their devices. However, this strength can also be a source of malicious exploitation. On Android, the problem has reached enormous proportions, as malware extensively abuses Accessibility Services. Over the years, Google has implemented multiple measures to address this phenomenon.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: bleepingcomputer
