Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

Laverne Cox brings back Mugler’s 2001 spider dress at Seattle Pride Gala

Far from the pitch, David Beckham remains soccer’s biggest star

Cardi B, Fat Joe and other musicians react

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » New Coyote Malware Variants Abuse Windows UI Automation to Steal Bank Credentials
Celebrities

New Coyote Malware Variants Abuse Windows UI Automation to Steal Bank Credentials

By July 23, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

July 23, 2025Ravi LakshmananWindows Security/Cryptocurrency

Windows Banking Trojan, known as Coyote, has become the first known malware strain to harvest sensitive information using a Windows accessibility framework called UI Automation (UIA).

“The new Coyote variant is targeting Brazilian users and uses the UIA to extract web addresses from 75 bank labs and credentials linked to cryptocurrency exchanges.”

First published by Kaspersky in 2024, Coyote is known for targeting Brazilian users. It has the ability to record keystrokes, capture screenshots, and provide overlays on top of login pages related to financial companies.

Part of the Microsoft .NET framework, UIA is a legitimate feature provided by Microsoft that allows screen readers and other assistive technology products to programmatically access user interface (UI) elements on the desktop.

Cybersecurity

The UIA has pointed out that it could be a potential route for abuse, including data theft, was previously demonstrated as a proof of concept (POC) by Akamai in December 2024, and that Web Infrastructure Company can be used to steal qualifications and execute code.

In a sense, Coyote’s latest modus operandi reflects a variety of Android banking Trojans discovered in the wild, often amassing valuable data using the accessibility services of the operating system.

Akamai’s analysis revealed that the malware calls the GetForeGroundWindow() Windows API to extract the title of the active window and compare it with a hard coding list of web addresses belonging to the target bank and cryptocurrency exchange.

“If no match is found, Coyote uses the UIA to parse the UI child elements of the window to identify the browser tab or address bar,” explained Peredo. “The contents of these UI elements are cross-referenced from the initial comparison with the same list of addresses.”

75 different financial institutions are targeting the latest versions of malware from 73, documented by Fortinet Fortiguard Labs in the beginning of January this year.

Cybersecurity

“In the absence of UIA, parsing sub-elements from another application is a non-trivial task,” Akamai added. “To be able to effectively read the contents of subelements within another application, developers need to have a very good understanding of the structure of a particular target application.”

“Coyotes can perform checks regardless of whether the malware is online or operating in offline mode. This will ensure that they successfully identify the victim’s bank or crypto exchange and are more likely to steal qualifications.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleProton’s new Privacy First AI Assistant encrypts all chats and does not keep logs
Next Article Eight months later, Swedish Unicorn Lovely Crosses a $100 million milestone

Related Posts

Laverne Cox brings back Mugler’s 2001 spider dress at Seattle Pride Gala

June 14, 2026

Taylor Swift transforms her date night style into velvet luxury

June 14, 2026

Nina Dobrev takes on bridal trends beyond white satin in Taorna

June 14, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Laverne Cox brings back Mugler’s 2001 spider dress at Seattle Pride Gala

Far from the pitch, David Beckham remains soccer’s biggest star

Cardi B, Fat Joe and other musicians react

Singer and producer dies in helicopter crash

Trending Posts

Laverne Cox brings back Mugler’s 2001 spider dress at Seattle Pride Gala

June 14, 2026

Cardi B, Fat Joe and other musicians react

June 14, 2026

Singer and producer dies in helicopter crash

June 14, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.