Coyote Trojan: A Digital Predator Infiltrating 70+ Financial Apps

Amber | Attack Report
Download PDF

The Coyote Banking Trojan is a sophisticated malware strain targeting Brazilian users, engineered to steal sensitive data from over 70 financial applications and more than 1,000 websites. It operates through a stealthy multi-stage attack chain, starting with malicious LNK files embedded with PowerShell commands. These commands initiate the deployment of Coyote, which employs keylogging, screenshot capture, and phishing overlays to harvest confidential credentials and sensitive information with precision.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox