Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Bion and Ransomexx Exploit SAP Netweaver Nafice for deploying Pipemagic Trojan

May 14, 2025

Samsung Patches Cve-2025-4632 used to deploy Mirai Botnet via Magicinfo 9 Exploit

May 14, 2025

Telegram Xinbi market associated with $ 8.4 billion in crystance, Romance scams, North Korea laundering

May 14, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Hoabot malicious programs target 6 Latin American
Global Security

Hoabot malicious programs target 6 Latin American

AdminBy AdminMay 14, 2025No Comments3 Mins Read
Horabot Malware
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


May 14, 2025Red LakshmananIntelligence / Threatening Windows

Malicious Hoabot software

Cybersecurity researchers have discovered a new phishing campaign used to distribute malware Horabot Aiming at Windows users in Latin American countries such as Mexico, Guatemala, Colombia, Peru, Chile and Argentina.

The company “uses the created emails that provide themselves with accounts and financial documents to deceive the victims in the opening of malicious investments and can steal the credentials via e -mail, from the crop and install bank trojans,” “Researcher Fortinet Fortiguard Labs Cara Labs – Note.

The activity observed by the network security company in April 2025 was primarily nominated by Hispanic users. The attacks were also discovered by the vicinage of the victims using the Audlook Com automation, effectively distributing malicious software to the corporate and personal networks.

Cybersecurity

In addition, the actors behind the company are performing various VBScript scripts, auto and powers for systemic exploration, theft of powers and reducing additional useful loads.

Horabob was First documented Cisco Talos in June 2023 as an orientation on Hispanic users in Latin America since November 2020. It is estimated that attacks are the work of an actor from Brazil.

Then last year Trustwave Spiderlabs disclosed Details of another phishing campaign aimed at the same region with malicious loads, which, according to, demonstrate similarity to malicious Hoabot programs.

Malicious Hoabot software

The latest set of attacks begins with a phishing email that uses baits with the subject on the account to attract users to the opening of the ZIP archive containing the PDF document. However, in reality, the attached ZIP file contains a malicious HTML file with HTML-coded Base64 data designed to achieve a remote server and load the useful load to the next stage.

Useful load – another ZIP archive containing the HTML (HTA) file (HTA) file, which is responsible for downloading the script on a remote server. Then the script introduces an external visual basic scenario (VBScript), which performs a number of checks that make it stop when Avast Antivirus is installed or works in a virtual setting.

Cybersecurity

VBScript continues to collect basic system information, highlight it on a remote server and receives additional useful loads, including the auto -script scenario that unleashes the banking trojan with the help of malicious dll and the PowerShell script, which instructed to distribute the fisher emails after creating the target address list, using the scanning of the contacts.

“Then malicious software continues to steal the browser data from a number of target web browsers, including Brave, Yandex, Epic Privicy Browser, Comodo Dragon, Cent Browser, Opera, Microsoft Edge and Google Chrome,” said the rope. “In addition to theft of data, Horabot monitors the victim’s behavior and introduces fake pop -up windows designed to capture sensitive credentials to enter.”

Found this article interesting? Keep track of us further Youter  and LinkedIn To read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Bion and Ransomexx Exploit SAP Netweaver Nafice for deploying Pipemagic Trojan

May 14, 2025

Samsung Patches Cve-2025-4632 used to deploy Mirai Botnet via Magicinfo 9 Exploit

May 14, 2025

Telegram Xinbi market associated with $ 8.4 billion in crystance, Romance scams, North Korea laundering

May 14, 2025

CTM360 determines the splash of phishing attacks, focused on meta -bizes -users

May 14, 2025

Why does the Security Antainment benefit all your security team

May 14, 2025

Earth AMIT BRIGHT BEHIND CHAPTERS DRUMBERS via ERP in Venom, Tidrone Company

May 14, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Bion and Ransomexx Exploit SAP Netweaver Nafice for deploying Pipemagic Trojan

May 14, 2025

Samsung Patches Cve-2025-4632 used to deploy Mirai Botnet via Magicinfo 9 Exploit

May 14, 2025

Telegram Xinbi market associated with $ 8.4 billion in crystance, Romance scams, North Korea laundering

May 14, 2025

Hoabot malicious programs target 6 Latin American

May 14, 2025

CTM360 determines the splash of phishing attacks, focused on meta -bizes -users

May 14, 2025

Why does the Security Antainment benefit all your security team

May 14, 2025

Earth AMIT BRIGHT BEHIND CHAPTERS DRUMBERS via ERP in Venom, Tidrone Company

May 14, 2025

Microsoft corrected 78 flaws, 5 zero days operated; CVSS 10 bugs affect the Azure Devops server

May 14, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Bion and Ransomexx Exploit SAP Netweaver Nafice for deploying Pipemagic Trojan

May 14, 2025

Samsung Patches Cve-2025-4632 used to deploy Mirai Botnet via Magicinfo 9 Exploit

May 14, 2025

Telegram Xinbi market associated with $ 8.4 billion in crystance, Romance scams, North Korea laundering

May 14, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.