Melcoz
MITRE ATT&CK: S0530 View on attack.mitre.org
Aliases: Melcoz
- First seen
- 2018-01-01 00:00:00
- Malware type
- trojan
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 14:45:45
Targeted industries: financial-services
Targeted regions: country_code:br country_code:cl country_code:mx country_code:es country_code:pt
Context
Melcoz is a banking trojan family built from the open source tool Remote Access PC. Melcoz was first observed in attacks in Brazil and since 2018 has spread to Chile, Mexico, Spain, and Portugal.
Detection coverage
- 208 Sigma rules
Malware & tools used
- Transmitted Data Manipulation (attack-pattern)
- AutoHotKey & AutoIT (attack-pattern)
- Msiexec (attack-pattern)
- Browser Session Hijacking (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- DLL (attack-pattern)
- Credentials from Web Browsers (attack-pattern)
- Visual Basic (attack-pattern)
- Software Packing (attack-pattern)
- Clipboard Data (attack-pattern)
- Malicious Link (attack-pattern)
- Spearphishing Link (attack-pattern)
Reports & references
- Kaspersky — 97779 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Melcoz (report)
- MITRE ATT&CK — S0530 (report)