Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Massive Android fraud operations are detected: iconade, kaleidoscope, malicious SMS software, NFC scams

July 3, 2025

Chinese hackers operate Ivanti CSA Zero-Days in attacks on the French government, telecommunications

July 3, 2025

More than 40 malicious Firefox extensions target cryptocurrency wallets, steel assets

July 3, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Hoabot malicious programs target 6 Latin American
Global Security

Hoabot malicious programs target 6 Latin American

AdminBy AdminMay 14, 2025No Comments3 Mins Read
Horabot Malware
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


May 14, 2025Red LakshmananIntelligence / Threatening Windows

Malicious Hoabot software

Cybersecurity researchers have discovered a new phishing campaign used to distribute malware Horabot Aiming at Windows users in Latin American countries such as Mexico, Guatemala, Colombia, Peru, Chile and Argentina.

The company “uses the created emails that provide themselves with accounts and financial documents to deceive the victims in the opening of malicious investments and can steal the credentials via e -mail, from the crop and install bank trojans,” “Researcher Fortinet Fortiguard Labs Cara Labs – Note.

The activity observed by the network security company in April 2025 was primarily nominated by Hispanic users. The attacks were also discovered by the vicinage of the victims using the Audlook Com automation, effectively distributing malicious software to the corporate and personal networks.

Cybersecurity

In addition, the actors behind the company are performing various VBScript scripts, auto and powers for systemic exploration, theft of powers and reducing additional useful loads.

Horabob was First documented Cisco Talos in June 2023 as an orientation on Hispanic users in Latin America since November 2020. It is estimated that attacks are the work of an actor from Brazil.

Then last year Trustwave Spiderlabs disclosed Details of another phishing campaign aimed at the same region with malicious loads, which, according to, demonstrate similarity to malicious Hoabot programs.

Malicious Hoabot software

The latest set of attacks begins with a phishing email that uses baits with the subject on the account to attract users to the opening of the ZIP archive containing the PDF document. However, in reality, the attached ZIP file contains a malicious HTML file with HTML-coded Base64 data designed to achieve a remote server and load the useful load to the next stage.

Useful load – another ZIP archive containing the HTML (HTA) file (HTA) file, which is responsible for downloading the script on a remote server. Then the script introduces an external visual basic scenario (VBScript), which performs a number of checks that make it stop when Avast Antivirus is installed or works in a virtual setting.

Cybersecurity

VBScript continues to collect basic system information, highlight it on a remote server and receives additional useful loads, including the auto -script scenario that unleashes the banking trojan with the help of malicious dll and the PowerShell script, which instructed to distribute the fisher emails after creating the target address list, using the scanning of the contacts.

“Then malicious software continues to steal the browser data from a number of target web browsers, including Brave, Yandex, Epic Privicy Browser, Comodo Dragon, Cent Browser, Opera, Microsoft Edge and Google Chrome,” said the rope. “In addition to theft of data, Horabot monitors the victim’s behavior and introduces fake pop -up windows designed to capture sensitive credentials to enter.”

Found this article interesting? Keep track of us further Youter  and LinkedIn To read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Massive Android fraud operations are detected: iconade, kaleidoscope, malicious SMS software, NFC scams

July 3, 2025

Chinese hackers operate Ivanti CSA Zero-Days in attacks on the French government, telecommunications

July 3, 2025

More than 40 malicious Firefox extensions target cryptocurrency wallets, steel assets

July 3, 2025

CISCO’s critical vulnerability in uniform grants on root access to static credentials

July 3, 2025

North Korean Hackers Target Web3 with malicious NIM software and use Clickfix in Babyshark

July 2, 2025

Hackers using PDFs to get yourself for Microsoft, Docusign and more in phishing campaigns return call

July 2, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Massive Android fraud operations are detected: iconade, kaleidoscope, malicious SMS software, NFC scams

July 3, 2025

Chinese hackers operate Ivanti CSA Zero-Days in attacks on the French government, telecommunications

July 3, 2025

More than 40 malicious Firefox extensions target cryptocurrency wallets, steel assets

July 3, 2025

CISCO’s critical vulnerability in uniform grants on root access to static credentials

July 3, 2025

North Korean Hackers Target Web3 with malicious NIM software and use Clickfix in Babyshark

July 2, 2025

Hackers using PDFs to get yourself for Microsoft, Docusign and more in phishing campaigns return call

July 2, 2025

This network traffic looks legal but it can hide a serious threat

July 2, 2025

US Sanctions of Russia

July 2, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Massive Android fraud operations are detected: iconade, kaleidoscope, malicious SMS software, NFC scams

July 3, 2025

Chinese hackers operate Ivanti CSA Zero-Days in attacks on the French government, telecommunications

July 3, 2025

More than 40 malicious Firefox extensions target cryptocurrency wallets, steel assets

July 3, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.