Categories: Technology

Mekotio: Beware of the banking Trojan!

Do you know who Mekotio is? It is a malicious software that aims to steal financial information, mainly credentials to access bank accounts or steal credit card information.

It was discovered for the first time in 2015, and in 2023 it continues with significant activity in several Latin American countries.

ESET Latin America, a proactive threat detection company, said that more than 70 variants of this banking trojan have been detected so far in 2023.

In this way, they carry out the theft of sensitive information from victims.

In addition to Latin American countries, there are also other countries where they are registered detection of this threat These are Spain, Italy and Ukraine, which shows that they have continued to expand their campaigns.

ESET analyzed the campaign distributed by Mekotio via electronic mail (spam) who use the issuance of an alleged invoice as bait and falsely present themselves as a well-known multinational company in Mexico.

The body of the email contains instructions for “open on Windows computer”. This is likely related to malware targeting this operating system.’

Mekotio is part of the list of banking trojans in Latin America, a family of malicious programs that have the ability to perform various actions that stand out by impersonating banks through fake pop-ups.

The message includes a link that, if clicked, downloads a ZIP file (ID-FACT.1684803774.zip) which pretends to be a supposed invoice, but when unzipped,
Windows installation file (MSI). This file contains several items.

Among them is a DLL file containing a variant of the Mekoti malware, which in this case ESET security solutions detect as Win32/Spy.Mekotio.GO.

“Besides stealing financial information, Mekotio is a Trojan capable of performing other malicious actions on a compromised computer,” says Camilo Gutiérrez Amaya, head of ESET’s Latin American Research Lab.

For example, it is capable of collecting information such as the operating system running on the victim’s computer, installed anti-fraud solutions or malware.

Also, malware It tries to stay hidden on the infected computer using startup registry keys and offers typical backdoor capabilities to attackers.

Source: Panama America

Share
Published by
Ella

Recent Posts

Terror suspect Chechen ‘hanged himself’ in Russian custody Egyptian President al-Sisi has been sworn in for a third term

On the same day of the terrorist attack on the Krokus City Hall in Moscow,…

1 year ago

Locals demand tourist tax for Tenerife: “Like a cancer consuming the island”

class="sc-cffd1e67-0 iQNQmc">1/4Residents of Tenerife have had enough of noisy and dirty tourists.It's too loud, the…

1 year ago

Agreement reached: this is how much Tuchel will receive for his departure from Bayern

class="sc-cffd1e67-0 iQNQmc">1/7Packing his things in Munich in the summer: Thomas Tuchel.After just over a year,…

1 year ago

Worst earthquake in 25 years in Taiwan +++ Number of deaths increased Is Russia running out of tanks? Now ‘Chinese coffins’ are used

At least seven people have been killed and 57 injured in severe earthquakes in the…

1 year ago

Now the moon should also have its own time (and its own clocks). These 11 photos and videos show just how intense the Taiwan earthquake was

The American space agency NASA would establish a uniform lunar time on behalf of the…

1 year ago

This is how the Swiss experienced the earthquake in Taiwan: “I saw a crack in the wall”

class="sc-cffd1e67-0 iQNQmc">1/8Bode Obwegeser was surprised by the earthquake while he was sleeping. “It was a…

1 year ago