Mekotio Banking Trojan Threatens Financial Systems in Latin America
Essential information
- Published
- 04/07/2024 10:49
- Modified
- 04/07/2024 10:54
- Tags
- 2024-07-04 banking trojan credential-theft mekotio
- Related entities
- 15 observables, 2 techniques (mitre), 1 malware, 5 others
Description
The Mekotio banking trojan, active since 2015, primarily targets Latin American countries to steal sensitive banking credentials through phishing emails containing malicious links or attachments. Upon execution, it gathers system information, connects to a command-and-control server, and performs credential theft, information gathering, and employs persistence mechanisms. The stolen data is sent back to the server for fraudulent activities. Users and organizations should follow security best practices to mitigate this threat.