Mekotio
- First seen
- 2018-06-01 00:00:00
- Malware type
- trojan
- Family
- Malware family
- Last IoC activity
- 2026-07-22 01:18:58
- Profile updated
- 2026-07-07 14:04:41
Targeted industries: financial-services
Targeted regions: country_code:br country_code:cl country_code:mx
Context
Mekotio is a banking trojan that mainly targets Latin American countries, particularly Brazil, Chile, and Mexico. It is known for stealing banking credentials through overlay attacks and is part of a larger family of trojans active in the region.
Reports & references
- advintel.io — Economic Growth Digital Inclusion Specialized Crime Financial Cyber Fraud In Latam (report)
- Microsoft — Html Smuggling Surges Highly Evasive Loader Technique Increasingly Used In Banking Malware Targeted Attacks (report)
- threatresearch.ext.hp.com — Hp Wolf Security Threat Insights Report Q1 2022 (report)
- interior.gob.es — 13552853 (report)
- therecord.media — Spain Arrests 16 For Distributing The Mekotio And Grandoreiro Banking Trojans (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Mekotio (report)
- blueliv.com — Rooty Dolphin Uses Mekotio To Target Bank Clients In South America And Europe (report)
- ESET — Mekotio These Arent The Security Updates Youre Looking For (report)
- research.checkpoint.com — Mekotio Banker Returns With Improved Stealth And Ancient Encryption (report)
- twitter.com — 1509185858146082816 (report)