HomeSecurityHorabot Banking Trojan: New campaign focusing on Mexico

Horabot Banking Trojan: New campaign focusing on Mexico

One of the most well-known banking trojans, Horabot, has resurfaced in a new cyberattack campaign targeting users in Mexico. The campaign is notable for sophistication , combining a banking trojan with a worm mechanism that turns any infected system into a tool for spreading phishing attacks.

Horabot Banking Trojan

A multi‑layered threat with financial motives

Horabot is based on Delphi and works in conjunction with a PowerShell-based spreader, creating a highly complex attack ecosystem. Researchers point out that this is one of the most sophisticated threats recorded in Latin America in recent years, with a clear goal of stealing banking information.

The attack does not necessarily exploit technical software vulnerabilities, but relies on deceiving the users themselves, which makes it even more dangerous.

See also: Interlock Ransomware: Cisco FMC Zero-Day Exploit

The fake CAPTCHA trap

The infection chain begins with a fake CAPTCHA page, which instructs the victim to open the Windows “Run” window and paste a command. With this simple action, the user activates a malicious HTA file, unknowingly starting the entire infection process.

This technique bypasses traditional security measures, as it does not require exploitation of any vulnerability, but relies solely on human behavior. In this way, the victim essentially becomes an accomplice of the attack.

The spread via email worm

One of the most dangerous features of the campaign is its ability to self-propagate via email. The worm collects contacts from the victim's mailbox and sends out mass phishing emails, usually disguised as invoices or confidential documents.

The emails are written in Spanish and primarily target users in Mexico, reinforcing their credibility. The malicious PDF attachmentincluded restarts the infection cycle, creating a self-feeding propagation network.

Horabot Banking Trojan: New campaign focusing on Mexico

Horabot: The technical analysis of the chain of infection

The attack consists of multiple stages, each of which adds a layer of obfuscation. After the HTA file is executed, a JavaScript loader from the attackers' infrastructure, which triggers an obfuscated VBScript.

VBScript delivers different versions of the code to each victim, making detection difficult. A more complex script then collects system information, such as IP, username, and operating system version, and sends it to a command-and-control server.

See also: Vidar Stealer 2.0 is distributed via fake game cheats

This is followed by the installation of persistence mechanisms and the loading of the final payload via AutoIT, which decrypts and executes the trojan directly in memory, avoiding detection by antivirus.

Connection with Brazil and extent of infection

The investigation uncovered more than 5,300 infected systems, 93% of which are located in Mexico. However, evidence in the code suggests that the creators of the attack may have roots in Brazil, as expressions in the Brazilian Portuguese language are used.

This geographic connection strengthens the image of an organized cybercrime ecosystem in Latin America, with cross‑border activity.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Communication techniques and detection

Horabot communicates with the control server via a custom TCP protocol, using XOR encryption . A distinctive “##” pattern is used to delimit the data, which can be exploited as a network-level detection indicator.

Despite the complexity of the attack, this recurring structure provides a reference point for IDS tools and monitoring systems.

See also: LeakNet Ransomware group uses ClickFix techniques

Horabot Banking Trojan: New campaign focusing on Mexico

Protection and defense measures

Experts recommend immediately restricting the execution of HTA files from untrusted sources and monitoring suspicious activity related to mshta. Additionally, using YARA and Suricata rules can help with early detection.

Equally important is user education, especially regarding fake CAPTCHA pages and malicious attachments. In an environment where social engineering plays a leading role, human vigilance remains the most critical level of defense against sophisticated threats like Horabot.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS