Karsten Hahn and I took a closer look at the latest #BBTok .NET loaders. In my first article on the #GDATATechblog we describe how to deobfuscate Trammy.dll and share new details about the BBTok infection chain.
https://www.gdatasoftware.com/blog/2024/09/38039-bbtok-deobfuscating-net-loader
@struppigel #GDATA

BBTok Targeting Brazil: Deobfuscating the .NET Loader with dnlib and PowerShell
A complex infection chain and a targeted approach make BBTok a very challenging piece of malware to examine. Analysts Marius Benthin and Karsten Hahn were able to examine a critical part of the infection chain and describe its inner workings in this latest article.

Insights on Cyber Threats Targeting Users and Enterprises in Mexico | Google Cloud Blog
Mexico faces a cyber threat landscape made up of a complex interplay of global and local threats.
Google Cloud Blog
New variant of BBTok Trojan targets users of +40 banks in LATAM
A new variant of a banking trojan, called BBTok, targets users of over 40 banks in Latin America, particularly Brazil and Mexico.
Security Affairs
BBTok Banking Trojan Targets Over 40 Latin American Banks in New Attack
An ongoing malware campaign is currently targeting Latin America, specifically users in Brazil and Mexico. The campaign is distributing a new variant of a banking trojan called BBTok. The BBTok ban…
CyberSec84 | Cybersecurity news.