216.73.217.22

Greedy Sponge Targets Mexico with AllaKore RAT and SystemBC

· Published 21/08/2025 16:16 · Modified 21/08/2025 20:25

Export JSON

Essential information

Published
21/08/2025 16:16
Modified
21/08/2025 20:25
Tags
2025-08-21 allakore rat credential-theft drive-by-download financial fraud geofencing mexico spear-phishing systembc
Related entities
1 intrusion sets (apt), 2 malware, 8 others

Description

A financially motivated threat group dubbed Greedy Sponge has been targeting Mexican organizations since 2021 with a modified version of and malware. The group uses and drive-by downloads to deliver custom packaged installers containing the RAT. Recent updates include improved , more potent secondary infections, and enhanced credential stealing capabilities. The AllaKore payload has been heavily modified to enable theft of banking credentials and authentication information. The group has shown consistent development of their tactics and techniques over time, demonstrating persistence and some level of operational success. Despite their longevity, they are not considered highly advanced, focusing primarily on against Mexican entities across various industries.

External references