AllaKore RAT Malware Targeting Mexican Firms with Financial Fraud Tricks
Monday, 29 January 2024
by Ayman Hamam
Mexican financial institutions are under the radar of a new spear-phishing campaign that delivers a modified version of an open-source remote access trojan called AllaKore RAT. The BlackBerry Research and Intelligence Team attributed the activity to an unknown Latin American-based financially motivated threat actor. The campaign has been active since at least 2021. “Lures use Mexican
- Published in News
Tagged under:
AllaKore RAT, ATM security, Banking fraud, BlackBerry Research and Intelligence Team, Command-and-control (C2) server, Crypto trading platforms, CVE-2024-0176, CVE-2024-0177), Cybersecurity Threats, Delphi-based RAT, Financial institutions., Financially motivated threat actor, Geolocation confirmation, IOActive, Lamassu Douro bitcoin ATMs, Malware, Mexican Social Security Institute (IMSS), Phishing attack, Physical access, Spear-phishing campaign, Swiss company, Vulnerabilities (CVE-2024-0175