PULSE NAME
How to uncover a Horabot campaign and detect this malware
WHITE Horabot AlienVault 2026-03-18 Modified: 2026-03-18
37
IOCs
MEDIUM VOLUME
This report details the discovery and analysis of a Horabot malware campaign targeting primarily Mexican users. The attack chain begins with a fake CAPTCHA page leading to multiple stages of obfuscated scripts, ultimately delivering an AutoIT loader and a Delphi-based banking Trojan. The malware employs sophisticated encryption techniques, anti-VM checks, and a custom protocol for C2 communication. It also includes a spreader component written in PowerShell that harvests and exfiltrates email addresses to distribute phishing emails. The analysis reveals Brazilian Portuguese comments in the code, suggesting the threat actor's origin. The report provides detection opportunities including YARA rules and hunting queries to identify this threat.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Horabot Metamorfo - S0455 Casbaneiro Ponteiro Metamorfo - S0455 Casbaneiro Zusy
Indicators of Compromise (2 / 37 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 b6144f80b32b37393b2da565326cd5085c6842e1 2026-03-18
FileHash-SHA1 e6a6e282a94c7724f5d9ac54d60d8cbd0e3ce892 2026-03-18