Back to Intel

Intel Node

The SOC Files: Time to “Sapecar”. Unpacking a new Horabot campaign in Mexico

lowmalware2026-03-18T11:00:14+00:00source excerpt
malwaredetectionemail

Source excerpt · The upstream feed supplied only part of this article.Read the original source →

Kaspersky SOC uncovered and analyzed a complex Horabot campaign in Mexico. In this article we share insights into how it is unleashed and how to hunt for this threat.

Introduction In this installment of our SOC Files series, we will walk you through a targeted campaign that our MDR team identified and hunted down a few months ago. It involves a threat known as Horabot , a bundle consisting of an infamous banking Trojan, an email spreader, and a notably complex attack chain. Although previous research has documented Horabot campaigns ( here and here ), our goal is to highlight how active this threat remains and to share some aspects not covered in those analyses. The starting point As usual, our story begins with an alert that popped up in one of our customers’ environments.

The rule that triggered it is generic yet effective at detecting suspicious mshta activity. The case progressed from that initial alert, but fortunately ended on a positive note.

Read Original Source