How to uncover a Horabot campaign and detect this malware
This report details the discovery and analysis of a Horabot malware campaign targeting primarily Mexican users. The attack chain begins with a fake CAPTCHA page leading to multiple stages of obfuscated scripts, ultimately delivering an AutoIT loader and a Delphi-based banking Trojan. The malware employs sophisticated encryption techniques, anti-VM checks, and a custom protocol for C2 communication. It also includes a spreader component written in PowerShell that harvests and exfiltrates email addresses to distribute phishing emails. The analysis reveals Brazilian Portuguese comments in the code, suggesting the threat actor's origin. The report provides detection opportunities including YARA rules and hunting queries to identify this threat.
Pulse ID: 69ba893ac080b945c5abb563
Pulse Link: https://otx.alienvault.com/pulse/69ba893ac080b945c5abb563
Pulse Author: AlienVault
Created: 2026-03-18 11:15:06
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Autoit #Bank #BankingTrojan #Brazil #CAPTCHA #CyberSecurity #Delphi #Email #Encryption #InfoSec #Malware #Mexican #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #Trojan #bot #AlienVault