Threat Advisories:

Greedy Sponge’s Stealthy RAT Attack in Mexico

Amber | Attack Report
Download PDF

A financially motivated cybercriminal group known as Greedy Sponge has been actively targeting organizations across Mexico using customized versions of the AllaKore remote access trojan (RAT). Their goal is to steal financial data to commit fraud. By delivering the malware through convincing phishing campaigns often disguised as policy updates or business-related files, they trick victims into installing malicious software. Once inside, the attackers not only steal valuable data but also deploy SystemBC, a secondary malware. Over time, the group has fine-tuned its tactics, improved its targeting of Mexican companies, and enhanced its evasion techniques. Their continued evolution and deliberate focus on the region underscore a persistent and growing threat to organizations in Mexico.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox

Cyber Horizons 2025

What Last Year’s Attacks Reveal About Today’s Risks

Watch the Webinar on-demand and get a FREE copy of our Cyber Horizons 2025 report.

Our Speakers
Speaker 1

Prateek Bhajanka Global Field CISO & Former Gartner Analyst Hive Pro Inc.

Speaker 2

Ankit Mani Manager Threat Intel HiveForce Labs

Speaker 3

Sreevani Tonipe Senior Threat Researcher HiveForce Labs