Mekotio

First seen
2018-06-01 00:00:00
Malware type
trojan
Family
Malware family
Last IoC activity
2026-07-22 01:18:58
Profile updated
2026-07-07 14:04:41

Targeted industries: financial-services

Targeted regions: country_code:br country_code:cl country_code:mx

Context

Mekotio is a banking trojan that mainly targets Latin American countries, particularly Brazil, Chile, and Mexico. It is known for stealing banking credentials through overlay attacks and is part of a larger family of trojans active in the region.

Reports & references

  • advintel.io — Economic Growth Digital Inclusion Specialized Crime Financial Cyber Fraud In Latam (report)
  • Microsoft — Html Smuggling Surges Highly Evasive Loader Technique Increasingly Used In Banking Malware Targeted Attacks (report)
  • threatresearch.ext.hp.com — Hp Wolf Security Threat Insights Report Q1 2022 (report)
  • interior.gob.es — 13552853 (report)
  • therecord.media — Spain Arrests 16 For Distributing The Mekotio And Grandoreiro Banking Trojans (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Mekotio (report)
  • blueliv.com — Rooty Dolphin Uses Mekotio To Target Bank Clients In South America And Europe (report)
  • ESET — Mekotio These Arent The Security Updates Youre Looking For (report)
  • research.checkpoint.com — Mekotio Banker Returns With Improved Stealth And Ancient Encryption (report)
  • twitter.com — 1509185858146082816 (report)

External references