Melcoz

MITRE ATT&CK: S0530 View on attack.mitre.org

Aliases: Melcoz

First seen
2018-01-01 00:00:00
Malware type
trojan
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 14:45:45

Targeted industries: financial-services

Targeted regions: country_code:br country_code:cl country_code:mx country_code:es country_code:pt

Context

Melcoz is a banking trojan family built from the open source tool Remote Access PC. Melcoz was first observed in attacks in Brazil and since 2018 has spread to Chile, Mexico, Spain, and Portugal.

Detection coverage

  • 208 Sigma rules

Malware & tools used

  • Transmitted Data Manipulation (attack-pattern)
  • AutoHotKey & AutoIT (attack-pattern)
  • Msiexec (attack-pattern)
  • Browser Session Hijacking (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • DLL (attack-pattern)
  • Credentials from Web Browsers (attack-pattern)
  • Visual Basic (attack-pattern)
  • Software Packing (attack-pattern)
  • Clipboard Data (attack-pattern)
  • Malicious Link (attack-pattern)
  • Spearphishing Link (attack-pattern)

Reports & references

  • Kaspersky — 97779 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Melcoz (report)
  • MITRE ATT&CK — S0530 (report)

External references