216.73.217.98

Mekotio Banking Trojan Threatens Financial Systems in Latin America

· Published 04/07/2024 10:49 · Modified 04/07/2024 10:54

Export JSON

Essential information

Published
04/07/2024 10:49
Modified
04/07/2024 10:54
Tags
2024-07-04 banking trojan credential-theft mekotio
Related entities
15 observables, 2 techniques (mitre), 1 malware, 5 others

Description

The , active since 2015, primarily targets Latin American countries to steal sensitive banking credentials through phishing emails containing malicious links or attachments. Upon execution, it gathers system information, connects to a command-and-control server, and performs credential theft, information gathering, and employs persistence mechanisms. The stolen data is sent back to the server for fraudulent activities. Users and organizations should follow security best practices to mitigate this threat.

External references