Banking Trojans: Mekotio Looks to Expand Targets, BBTok Abuses Utility Command

September 5, 2024 at 05:41AM Cybercriminals are targeting Latin American users with a rise in phishing scams, deploying banking Trojans like Mekotio and BBTok. Mekotio’s latest variant suggests a broadening of targets, while BBTok evades detection by abusing MSBuild.exe. Sophisticated phishing attacks are compromising financial systems, prompting the urgent need for enhanced cybersecurity measures and … Read more

Blind Eagle Hackers Exploit Spear-Phishing to Deploy RATs in Latin America

August 20, 2024 at 02:22AM Cybersecurity researchers have reported ongoing attacks by Blind Eagle, an adaptable threat actor targeting entities and individuals in Latin American nations. The group employs spear-phishing tactics, geographical redirection, and process injection techniques to distribute trojans like AsyncRAT and NjRAT, enabling cyber espionage and financial credential theft campaigns. Kaspersky warns of … Read more

Microsoft Azure outage takes down services across North America

August 5, 2024 at 05:08PM Microsoft successfully resolved a two-hour Azure outage that disrupted multiple services in North and Latin America. Based on the meeting notes, the key takeaway is that Microsoft has successfully mitigated an Azure outage that affected multiple services for customers across North and Latin America, lasting more than two hours. Full … Read more

Cybercriminals Exploit CrowdStrike Update Mishap to Distribute Remcos RAT Malware

July 20, 2024 at 01:30PM CrowdStrike’s flawed Windows update led to a global IT disruption, exploited by threat actors to distribute Remcos RAT to Latin American customers using a disguised hotfix. The attack involves a ZIP file containing a malware loader and Spanish instructions, targeting CrowdStrike’s Latin America-based customers. Malicious actors are also setting up … Read more

Poco RAT Burrows Deep Into Mining Sector

July 10, 2024 at 11:03AM Unidentified attackers are propagating a novel credential-harvesting remote access trojan, dubbed Poco RAT, mainly targeting sectors in Latin America. Using email campaigns with Spanish-themed finance lures and Google Drive links, the malware evades email gateways. It is built for anti-analysis, communication with a C2 server, and file delivery, while relying … Read more

Experts Warn of Mekotio Banking Trojan Targeting Latin American Countries

July 8, 2024 at 06:24AM Latin American financial institutions face a surge in cyber attacks from the Mekotio banking trojan, targeting countries like Brazil and Mexico to steal banking credentials. Trend Micro observed a rise in attacks distributing this Windows malware, as well as the emergence of a new trojan codenamed Red Mongoose Daemon, posing … Read more

Mekotio Banking Trojan Threatens Financial Systems in Latin America

July 4, 2024 at 05:14AM The Mekotio banking trojan is a significant threat to financial systems in Latin America, targeting countries such as Brazil, Chile, Mexico, Spain, and Peru. It infiltrates systems through phishing emails, aiming to steal sensitive information, particularly banking credentials. Users can protect themselves by being cautious with emails, avoiding clicking on … Read more

‘The Mask’ Espionage Group Resurfaces After 10-Year Hiatus

May 9, 2024 at 05:52PM The “Careto” APT group, inactive for over a decade, has reemerged in cyber-espionage targeting entities in Latin America and Central Africa. Kaspersky researchers have identified previous victims and new targets, emphasizing the need to remain vigilant against long-dormant APTs. The group’s sophisticated attacks involve custom techniques and versatile implants, showcasing … Read more

Cybercriminals Targeting Latin America with Sophisticated Phishing Scheme

April 8, 2024 at 05:15AM A new phishing campaign targets Latin American users by sending a phishing email with a ZIP file attachment containing a malicious HTML file posing as an invoice. When the link in the HTML file is opened from a Mexican IP address, a CAPTCHA verification page opens, leading to a malicious … Read more

Chilean telecom giant GTD hit by the Rorschach ransomware gang

October 25, 2023 at 06:07PM Chile’s telecommunications company, Grupo GTD, experienced a cyberattack on its Infrastructure as a Service (IaaS) platform, resulting in disruptions to services, including data centers, internet access, and Voice-over-IP (VoIP). The attack involved the Rorschach ransomware variant, which utilizes DLL sideloading vulnerabilities in legitimate executables to inject a ransomware payload and … Read more