Security Snippets: New trojan Coyote

Hogan Lovells
Contact

Hogan Lovells[co-author: Rachel Dalton]

Coyote, a new Brazilian malware, is currently hunting down credentials for sixty-one (61) different banking applications. Researchers expect the malware to spread internationally.


Russian cybersecurity firm Kaspersky has identified a new malware, “Coyote,” which has been seen to be broadly targeted banking applications in Brazil, with sixty-one (61) banks affected so far. Coyote has a sophisticated infection chain that first, utilizes the Squirrel installer for distribution. Squirrel is a legitimate open source tool that is used to install and update Windows desktop applications. To complete its infection, Coyote leverages NodeJS and Nim. Coyote uses string obfuscation with AES encryption to hide from detection. It is currently known for twelve (12) malicious functionalities.

Because of Coyote’s unique infection chain, researchers anticipate it will be harder for cybersecurity teams to detect. Currently, 90% of Coyote infections have originated from Brazil, but companies outside of Brazil will also want to be on the lookout for this banking Trojan as it continues to develop. Historically, Brazilian banking Trojans have been used to attack banks globally.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Hogan Lovells | Attorney Advertising

Written by:

Hogan Lovells
Contact
more
less

Hogan Lovells on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide