PULSE NAME
How to uncover a Horabot campaign and detect this malware
WHITE Horabot AlienVault 2026-03-18 Modified: 2026-03-18
37
IOCs
MEDIUM VOLUME
This report details the discovery and analysis of a Horabot malware campaign targeting primarily Mexican users. The attack chain begins with a fake CAPTCHA page leading to multiple stages of obfuscated scripts, ultimately delivering an AutoIT loader and a Delphi-based banking Trojan. The malware employs sophisticated encryption techniques, anti-VM checks, and a custom protocol for C2 communication. It also includes a spreader component written in PowerShell that harvests and exfiltrates email addresses to distribute phishing emails. The analysis reveals Brazilian Portuguese comments in the code, suggesting the threat actor's origin. The report provides detection opportunities including YARA rules and hunting queries to identify this threat.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Horabot Metamorfo - S0455 Casbaneiro Ponteiro Metamorfo - S0455 Casbaneiro Zusy
Indicators of Compromise (3 / 37 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 4caa797130b5f7116f11c0b48013e430 2026-03-18
FileHash-MD5 6272ef6ac1de8fb4bdd4a760be7ba5ed 2026-03-18
FileHash-MD5 c882d948d44a65019df54b0b2996677f 2026-03-18