The Mekotio banking trojan is a sophisticated piece of malware that has been active since at least 2015, primarily targeting Latin American countries with the goal of stealing sensitive information — particularly banking credentials — from its targets.
Originating in the Latin American region, it has been particularly prolific in Brazil, Chile, Mexico, Spain, and Peru. Furthermore, Mekotio seems to share a common origin with other notable Latin American banking malware such as Grandoreiro, which was disrupted by law enforcement earlier this year. Mekotio is often delivered through phishing emails, employing social engineering to trick users into interacting with malicious links or attachments. Trend Micro recently seen a surge in attacks involving Mekotio among their customers.
Read more…
Source: Trend Micro
Related:
- Zombie Card: An expired Visa credit card can be used for purchases
August 21, 2026
Did you know there is still a good reason to physically destroy your expired credit card? Scientific research found that the expiration date used by payment terminals on some contactless cards was not effectively protected against tampering. University of Massachusetts Amherst researchers Raja Hasnain Anwar, Gerard DeCunha, and Muhammad Taqi Raza tested contactless cards across Visa, Mastercard, Discover, ...
- New Android malware lets criminals use your bank card in real time
August 13, 2026
Researchers at Group-IB have discovered a new NFC relay malware family, purpose-built to capture live card data via NFC and forward it in real time to attackers. They dubbed it “WindRelay.” NFC (Near Field Communication) is wireless technology that allows devices such as smartphones, payment cards, and payment terminals to communicate when they’re very close together. So, ...
- Top US hedge funds targeted by major vishing campaign
August 9, 2026
Some of the biggest US hedge funds and law firms have been targeted by a highly sophisticated data breach and extortion campaign, conducted by a group of criminals previously known as BlackFile, experts have warned. BlackFile (or Redact, as the group is now calling itself) has a relatively simple modus operandi, also used by ShinyHunters – ...
- Durov’s bank accounts frozen after terrorist tag applied
July 30, 2026
Telegram co-founder Pavel Durov will not be able to access his bank accounts in Russia after placement on the list of terrorists by financial watchdog Rosfinmonitoring earlier on Thursday, lawyer Dmitry Agranovsky told TASS. Since 2022, Russia has recorded 153,000 crimes committed using Telegram, including the organization of a terrorist attack at the Crocus City Hall, ...
- Warning: Scammers are using FaceTime to empty bank accounts
July 14, 2026
Apple is urging users to treat any suspicious FaceTime call or message as untrusted, especially if it involves payments, refunds, password resets, or requests for personal information. This warning appears in a broader Apple support article about scams that target iPhone and iPad users through social engineering. Apple says attackers may contact people by phone calls, FaceTime, text ...
- Accenture confirms breach after hacker steals 35GB of source code and other data
July 9, 2026
Accenture has confirmed suffering a cyberattack, days after threat actors started selling an archive allegedly coming from the firm. “We are aware of this isolated matter, and we have remediated its source. There is no impact to Accenture operations and service delivery,” Accenture said in a statement. It follows a relatively unknown threat actor called 888 posting ...

