FEATURED SECURITY REPORT: New Botnet Malware ‘ Horabot ‘ Targets Spanish Speaking Users in Latin America

Published on

in

@acenewsservices
@acenewsservices

This is our daily post that is shared across Twitter & Telegram and published first on here with Kindness & Love XX on peace-truth.com/

#AceNewsRoom in Kindness & Wisdom provides News & Views @acebreakingnews

Ace Press News From Cutting Room Floor: Published: June.01: 2023:

#AceSecurityDesk – BREAKING – Spanish-speaking users in Latin America have been at the receiving end of a new botnet malware dubbed Horabot since at least November 2020.

@acenewsservices

Horabot enables the threat actor to control the victim’s Outlook mailbox, exfiltrate contacts’ email addresses, and send phishing emails with malicious HTML attachments to all addresses in the victim’s mailbox,” Cisco Talos researcher Chetan Raghuprasad said.

@acenewsservices

The botnet program also delivers a Windows-based financial trojan and a spam tool to harvest online banking credentials as well as compromise Gmail, Outlook, and Yahoo! webmail accounts to blast spam emails.

The cybersecurity firm said a majority of the infections are located in Mexico, with limited victims identified in Uruguay, Brazil, Venezuela, Argentina, Guatemala, and Panama. The threat actor behind the campaign is believed to be in Brazil.

Targeted users of the ongoing campaign primarily span accounting, construction and engineering, wholesale distribution, and investment verticals, although it’s suspected that other sectors in the region may also be affected.

The attacks start with phishing emails bearing tax-themed lures that entice the recipients into opening an HTML attachment, which, in turn, embeds a link containing a RAR archive.

@acenewsservices

Opening the contents of the file results in the execution of a PowerShell downloader script that’s responsible for retrieving a ZIP file containing the main payloads from a remote server and rebooting the machine.

The system restart also serves as a launchpad for the banking trojan and the spam tool, allowing the threat actor to steal data, log keystrokes, capture screenshots, and disseminate additional phishing emails to the victim’s contacts.

@acenewsservices

“This campaign involves a multi-stage attack chain that begins with a phishing email and leads to payload delivery through the execution of a PowerShell downloader script and sideloading to legitimate executables,” Raghuprasad said.

Botnet Malware
@acenewsservices

The banking trojan is a 32-bit Windows DLL written in the Delphi programming language, and shares overlaps with other Brazilian malware families like Mekotio and Casbaneiro.

@acenewsservices

Horabot, for its part, is an Outlook phishing botnet program written in PowerShell that’s capable of sending phishing emails to all email addresses in the victim’s mailbox to propagate the infection. It’s also a deliberate attempt to minimize the threat actor’s phishing infrastructure from being exposed.

The disclosure arrives a week after SentinelOne attributed an unknown Brazilian threat actor to a long-running campaign targeting more than 30 Portuguese financial institutions with information-stealing malware since 2021.

It also follows the discovery of a new Android banking trojan dubbed PixBankBot that abuses the operating system’s accessibility services to conduct fraudulent money transfers over the Brazilian PIX payments platform.

PixBankBot is also the latest example of malware that specifically focuses on Brazilian banks, featuring capabilities similar to BrasDex, PixPirate, and GoatRAT that have been spotted in recent months.

If anything, the developments represent yet another iteration of a broader group of financially motivated hacking efforts emanating from Brazil, making it crucial that users remain vigilant to avoid falling prey to such threats.

FEATURED HACKERS NEWS REPORT

Editor says …Sterling Publishing & Media Service Agency is not responsible for the content of external site or from any reports, posts or links, and can also be found here on Telegram: https://t.me/acenewsdaily and thanks for following as always appreciate every like, reblog or retweet and comment thank you

@acenewsservices

Hey!

Hey there, fellow Robloxian! Whether you’re here to discover hidden gem games, level up your building skills, or just stay in the loop with the latest events, you’re in the right place. This blog is all about sharing the coolest things in the Roblox universe—from developer tips to epic game reviews. So grab your Bloxy Cola, hit that follow button, and let’s explore the world of Roblox together! 🚀


Join the Club

Stay updated with our latest tips and other news by joining our newsletter.

Discover more from Peace & Truth

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from Peace & Truth

Subscribe now to keep reading and get access to the full archive.

Continue reading