Close Menu
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Español
    • Português
What's Hot

Samsung Patches CVE-2025-4632 Used for Mirai Botnet deployment via Magicinfo 9 Exploit

Trump’s Oil’s preferred price is $40-50 based on his social media post

Xinbi Telegram Market is $840 million in crypto crime, romance fraud, North Korean laundry

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Español
    • Português
Fyself News
Home » Horabot Malware targets six Latin American countries using invoice-themed phishing emails
Identity

Horabot Malware targets six Latin American countries using invoice-themed phishing emails

userBy userMay 14, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

May 14, 2025Ravi LakshmananWindows Security/Threat Intelligence

Horabot Malware

Cybersecurity researchers have discovered a new phishing campaign that is used to distribute malware called Horabot, targeting Windows users in Latin American countries such as Mexico, Guatemala, Colombia, Peru, Chile and Argentina.

The campaign “uses crafted emails to “make up invoices or financial documents, treat victims, open malicious attachments, steal email credentials, harvest contact lists, and allow bank Trojans to be installed,” said Cara Lin, a researcher at Fortinet Fortiguard Labs.

The activity observed by network security companies in April 2025 was primarily selecting Spanish-speaking users. Attacks are also known to use Outlook Com automation to send phishing messages from victims’ mailboxes and effectively propagate malware horizontally within the company or personal network.

Cybersecurity

Additionally, the threat actors behind the campaign run various VBScript, car, and PowerShell scripts to conduct system reconnaissance, steal qualifications, and drop additional payloads.

Horabot was first documented in June 2023 by Cisco Talos as targeting Spanish-speaking users in Latin America since at least November 2020. Attacks are rated as the work of Brazilian threat actors.

Then last year, Trustwave SpiderLabs revealed details of another phishing campaign targeting the same region with malicious payloads that demonstrate similarity and similarity to Horabot malware.

Horabot Malware

The latest attack set starts with a phishing email that uses invoice-themed lures to tempt users to open a ZIP archive containing PDF documents. However, in reality, the attached ZIP file contains a malicious HTML file with Base64 encoded HTML data designed to reach out to a remote server and download the next stage payload.

A payload is another ZIP archive containing HTML application (HTA) files that are responsible for loading scripts hosted on a remote server. The script then inserts an external visual basic script (VBScript) that performs a series of checks that will be terminated if Avast Antivirus is installed or is running in a virtual environment.

Cybersecurity

VBScript goes to get additional payloads, such as car scripts that collect basic system information, extract it to remote servers, and unleash banking trojans by malicious DLLs, and PowerShell scripts that impose phishing emails spread after constructing a list of target email addresses that have scanned contact data within the scope of your vision.

“Malware steals browser-related data from a variety of target web browsers, including Brave, Yandex, Epic Privacy Browser, Comodo Dragon, Cent Browser, Opera, Microsoft Edge, Google Chrome, and more. “In addition to data theft, Horabot injects fake pop-up windows designed to monitor victim behavior and capture sensitive user login credentials.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleIsraeli attack on Gaza kills 70 when ceasefire talk continues | Israeli-Palestinian conflict news
Next Article Partners with PayPal, PayPal and PayPal for Chat AI Shopping
user
  • Website

Related Posts

Samsung Patches CVE-2025-4632 Used for Mirai Botnet deployment via Magicinfo 9 Exploit

May 14, 2025

Xinbi Telegram Market is $840 million in crypto crime, romance fraud, North Korean laundry

May 14, 2025

CTM360 Identifies a surge in phishing attacks targeting metabusiness users

May 14, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Samsung Patches CVE-2025-4632 Used for Mirai Botnet deployment via Magicinfo 9 Exploit

Trump’s Oil’s preferred price is $40-50 based on his social media post

Xinbi Telegram Market is $840 million in crypto crime, romance fraud, North Korean laundry

As combat resumes in Tripoli, Libya, we are seeking calmness | Conflict News

Trending Posts

As combat resumes in Tripoli, Libya, we are seeking calmness | Conflict News

May 14, 2025

Did the US flutter first in the tariff war with China? |Trade War News

May 14, 2025

Israeli attack on Gaza kills 70 when ceasefire talk continues | Israeli-Palestinian conflict news

May 14, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

AI infrastructure startup TensorWave raises $100 million to meet the rising demand for AI calculations

DataBricks acquires serverless database startup neon for $1 billion to boost AI agent development

All the steps you can take to make your online bet safer

Etoro is revealed at a $52 IPO and is worth $4.2 billion amid the retail and crypto boom

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.