PULSE NAME
How to uncover a Horabot campaign and detect this malware
WHITE Horabot AlienVault 2026-03-18 Modified: 2026-03-18
37
IOCs
MEDIUM VOLUME
This report details the discovery and analysis of a Horabot malware campaign targeting primarily Mexican users. The attack chain begins with a fake CAPTCHA page leading to multiple stages of obfuscated scripts, ultimately delivering an AutoIT loader and a Delphi-based banking Trojan. The malware employs sophisticated encryption techniques, anti-VM checks, and a custom protocol for C2 communication. It also includes a spreader component written in PowerShell that harvests and exfiltrates email addresses to distribute phishing emails. The analysis reveals Brazilian Portuguese comments in the code, suggesting the threat actor's origin. The report provides detection opportunities including YARA rules and hunting queries to identify this threat.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Horabot Metamorfo - S0455 Casbaneiro Ponteiro Metamorfo - S0455 Casbaneiro Zusy
Indicators of Compromise (1 / 37 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 474b25badb40f524a7b2fe089e51eb7dbafd2e3e03a9f6750f72055d05b13d76 2026-03-18