Threat Analysis: DCRat presence growing in Latin America
June 8, 2025, 4:55 p.m.
Description
Hive0131 is conducting email campaigns targeting users in Colombia with fake electronic notifications of criminal proceedings, purportedly from The Judiciary of Colombia. The campaigns deliver DCRat, a banking trojan operated as Malware-as-a-Service, through embedded links or PDF lures. DCRat's presence has increased in Latin America since 2024. The infection chain involves downloading a loader called VMDetectLoader, which uses process hollowing to inject DCRat into memory. VMDetectLoader can detect virtual machines and create persistence through scheduled tasks or registry keys. DCRat has various capabilities including recording victims, file manipulation, and keystroke logging. IBM X-Force assesses that Latin America will continue facing targeting from actors deploying banking trojans via phishing campaigns.
Tags
Date
- Created: June 6, 2025, 11:02 a.m.
- Published: June 6, 2025, 11:02 a.m.
- Modified: June 8, 2025, 4:55 p.m.
Indicators
- 1603c606d62e7794da09c51ca7f321bb5550449165b4fe81153020021cbce140
- 0df13fd42fb4a4374981474ea87895a3830eddcc7f3bd494e76acd604c4004f7
- feb18.freeddns.org
Additional Informations
- Finance
- Government
- Colombia