Home/Threat Actor/Mekotio
Threat Actor

Mekotio

mekotio · latin_america_brazilian_organized_cybercrime · active since 2015

Mekotio (canonical ESET August 2020 industry naming; sometimes equated with Melcoz per Kaspersky Tetrade classification per CyberScoop + The Hacker News "Researchers with Kaspersky grouped Mekotio also known as Melcoz into a larger group they called Tetrade", naming convention dispute between ESET treating Mekotio as distinct + Kaspersky treating Mekotio = Melcoz as Tetrade family member alongside Guildma + Javali + Grandoreiro) is a Latin American banking trojan active since at least 2015 with Brazilian-origin operators, operationally cluster- defining for sustained Spanish/Portuguese-speaking country targeting tradecraft.

standalone malware platform cluster paralleling grandoreiro + guildma_astaroth in Latin American banking trojan operators cell.

Brazilian-origin organized cybercrime attribution via ESET WeLiveSecurity canonical August 2020 first documentation establishing Brazilian- origin + Latin American banking trojan classification (per ESET via The Hacker News: "Mekotio shares common characteristics for this type of malware, such as being written in Delphi, using fake pop-up windows, containing backdoor functionality and targeting Spanish-and Portuguese-speaking countries") + Spanish Civil Guard canonical July 2021 arrest of 16 distribution-network individuals targeting European users via social engineering campaigns delivering both Mekotio + Grandoreiro (~€300,000 stolen + €3.5M attempted transfer blocked per ESET December 2021 "Dirty Dozen of Latin America: From Amavaldo to Zumanek" retrospective with ESET telemetry assessing "Mekotio seems to have taken a much larger hit than Grandoreiro" indicating arrested people more connected to Mekotio) + Check Point Research canonical November 2021 evolved variant disclosure (Arie Olshtein + Abedalla Hadra + Kobi Eisenkraft Team Leader) detecting + blocking 100+ post-arrest attacks targeting Brazil + Chile + Mexico + Spain + Peru with new substitution cipher obfuscation + new Themida commercial packer version with sophisticated encryption + anti-debug + anti-monitoring (per Eisenkraft: "Although the Spanish Civil Guard announced the arrest of 16 people involved with Mekotio distribution in July 2021, it appears the gang behind the malware is still active") + Trend Micro Research canonical July 4, 2024 renewed warning "Mekotio Banking Trojan Threatens Financial Systems in Latin America" identifying recent attack surge + persistent evolving threat to Latin American financial systems + ESET January 2024 Grandoreiro disruption operator-relation discovery (per ESET ETeC 2024: "discovered that one of the arrested suspects had very close relations with Mekotio, another infamous LATAM banking trojan", cluster-cell coherence with Grandoreiro cluster via shared operator network); operational attack architecture comprising Spanish/Portuguese phishing emails + ZIP archive + malicious link multi-stage delivery infrastructure for detection avoidance + spoofed email lures including "digital tax receipt pending submission" (Check Point November 2021) + MSI installer payload delivery alongside direct ZIP attachment per CyberScoop + cluster-defining substitution cipher obfuscation tradecraft (ancient encryption method to obfuscate file content + hide first attack module, allows undetected execution by most antivirus products) + cluster-defining Themida commercial packer sophisticated encryption + anti-debug + anti- monitoring per Check Point + cluster-defining fake banking login pop-up overlays GUI input capture for banking credential theft (Mekotio main goal is banking credential theft via fake pop-ups mimicking legitimate banking sites tricking users into entering details) + screenshot + keylogging + clipboard data collection signature comprehensive information gathering + Microsoft Azure + Amazon AWS cloud environments file hosting per Check Point + registry Run keys + scheduled tasks persistence.

Brazilian- European distribution gang collaboration model signature per Check Point Eisenkraft "operates from Brazil and collaborates with European gangs to distribute the malware".

sustained Spanish/ Portuguese-speaking country focus (Brazil + Chile + Mexico + Spain + Peru + Portugal consistent through 2015-2026 with secondary European expansion to Italy + France + Belgium small campaigns per ESET); persistent post-arrest evolution signature, gang continued operations after July 2021 Spanish arrests + November 2021 Check Point evolved variant + July 2024 Trend Micro renewed warning demonstrated sustained operational tempo (per ESET: "Even though Mekotio went very quiet for almost two months after the arrest, ESET continues to see new campaigns distributing Mekotio at the time of writing"); Delphi programming language origin signature typical Latin American banking trojan.

Scitum (Mexico) July 2024 disclosure of Red Mongoose Daemon adjacent Latin American banking trojan using MSI droppers via invoices + tax notes phishing demonstrates continued LATAM banking trojan family expansion through 2024; cluster fills the most-sustained-Spanish-Portuguese- targeting position in Latin American banking trojan operators cell.

canonical illustration of Brazilian- European distribution gang collaboration model + Themida packer + substitution cipher evasion tradecraft + sustained post-arrest operational resilience cited in essentially all subsequent Latin American banking trojan + Spanish-speaking country financial cybercrime industry analyses through 2015- 2026 period.

latin_america_brazilian_organized_cybercrime confidence: high 10 aliases
Sigma rules200 YARA rules0 Live IOCs0 CVEs exploited0

Profile

Mekotio (canonical ESET August 2020 industry naming; sometimes equated with Melcoz per Kaspersky Tetrade classification per CyberScoop + The Hacker News: "Researchers with Kaspersky grouped Mekotio (also known as 'Melcoz') into a larger group they called Tetrade") is a Latin American banking trojan active since at least 2015 with Brazilian-origin operators, operationally cluster-defining for sustained Spanish/ Portuguese-speaking country targeting tradecraft. Brazilian-origin organized cybercrime attribution via ESET canonical August 2020 first documentation + Spanish Civil Guard canonical July 2021 arrest of 16 distribution-network individuals (joint Mekotio + Grandoreiro) + Check Point Research canonical November 2021 evolved variant disclosure + Trend Micro canonical July 2024 renewed warning + ESET January 2024 Grandoreiro disruption Mekotio operator- relation discovery. Standalone malware platform cluster paralleling grandoreiro + guildma_astaroth in the Latin American banking trojan operators cell.

Operational target profile
  • Brazil + Chile + Mexico + Spain + Peru + Portugal primary consistent targets.
  • Italy + France + Belgium secondary European expansion (small campaigns per ESET)
  • Latin American banks + financial institutions primary target category.
  • €300,000 stolen + €3.5M attempted transfer blocked per Spanish Civil Guard July 2021 Operational attack architecture: (1) Spanish/Portuguese phishing emails as primary infection vector (2) ZIP archive + malicious link multi-stage delivery for detection avoidance per Check Point (3) Spoofed email lures including "digital tax receipt pending submission" per Check Point November 2021 (4) MSI installer payload delivery alongside direct ZIP attachment per CyberScoop (5) Substitution cipher obfuscation (cluster- defining 2021+ evolution): ancient encryption method to obfuscate file content + hide first attack module (6) Themida commercial packer (cluster-defining): sophisticated encryption + anti-debug + anti-monitoring tradecraft per Check Point (7) Fake banking login pop-up overlays (cluster- defining): GUI input capture for banking credential theft (8) Screenshot + keylogging + clipboard data collection (signature): comprehensive information gathering (9) Microsoft + Amazon cloud environments file hosting (signature): Microsoft Azure + Amazon AWS cloud abuse for malicious file hosting per Check Point (10) Registry Run keys + scheduled tasks persistence (signature) Signature operational tradecraft:.
  • Sustained Spanish/Portuguese-speaking country focus (cluster-defining): Brazil + Chile + Mexico + Spain + Peru + Portugal consistent through 2015- 2026.
  • Brazilian-European distribution gang collaboration model (signature): per Check Point Eisenkraft, "operates from Brazil and collaborates with European gangs to distribute the malware".
  • Multi-stage delivery infrastructure (signature): for detection avoidance per Check Point.
  • Substitution cipher + Themida packer evasion (cluster-defining 2021+ evolution): avoid most antivirus detection.
  • Fake banking pop-up overlay GUI input capture (signature): typical Latin American banking trojan tradecraft.
  • Delphi programming language origin (signature typical Latin American banking trojan).
  • Close operator relations to Grandoreiro per ESET January 2024 disruption (signature): cluster-cell coherence via shared operator network.
  • Sometimes equated with Melcoz per Kaspersky Tetrade classification: naming convention dispute between ESET (Mekotio distinct) and Kaspersky (Mekotio = Melcoz part of Tetrade)
  • Persistent post-arrest evolution (signature): gang continued operations after July 2021 Spanish arrests + November 2021 + July 2024 demonstrated sustained operational tempo.
  • Quiet ~2 months after arrest then continued activity per ESET: signature operator resilience pattern The cluster fills the most-sustained-Spanish- Portuguese-targeting position in the Latin American banking trojan operators cell.

Aliases

10
mekotiomekotio_banking_trojanmekotio_malwaremelcozmekotio latam banking trojanmekotio spanish portuguese speaking countriesmekotio delphi banking trojanmekotio brazil chile mexico spain peru portugalmekotio themida packer substitution ciphermekotio check point 2021 evolved variant

Adversary Emulation Plan

8 steps
Runnable Caldera emulation profile Check - Profile to check proper platform configuration. Observe outputs to verify.. Ordered along the attack lifecycle; each step maps to an ATT&CK technique with a concrete executor command. For authorized red-team / purple-team exercises only.
0 discovery T1033 · System Owner/User Discovery darwin, linux, windows
Current User
whoami
1 discovery T1083 · File and Directory Discovery darwin, linux, windows
Print Working Directory
pwd
2 discovery T1083 · File and Directory Discovery darwin, linux, windows
List Directory
ls
3 discovery T1057 · Process Discovery darwin, linux, windows
View Processes
ps
4 discovery T1016 · System Network Configuration Discovery darwin, linux, windows
Network Interface Configuration
sudo ifconfig
5 discovery T1518 · Software Discovery darwin, linux
Check Go
which go
6 discovery T1518 · Software Discovery darwin, linux
Check Chrome
which google-chrome
7 discovery T1518 · Software Discovery darwin, linux, windows
Check Python
python3 --version;python2 --version;python --version

Notable Campaigns

9
2024Trend Micro Canonical July 2024 Renewed Warning
2024Scitum Red Mongoose Daemon Adjacent Latin American Banking Trojan (July 2024)
2024ESET January 2024 Grandoreiro Disruption, Mekotio Operator-Relation Discovery
2021Spanish Civil Guard Joint Mekotio + Grandoreiro Arrests (July 2021)
2021Check Point Research Evolved Variant Canonical Disclosure (November 2021)
2021ESET 'Dirty Dozen of Latin America' Canonical Retrospective (December 15, 2021)
2020Mekotio European Expansion + Spanish Targeting (2020)
2015-2026Continued Industry Reference Status (2015-2026)
2015Mekotio Origin, Latin American Targeting (2015)

Attribution & Reporting

Attributed by
ESET WeLiveSecurity (canonical August 2020 first documentation + December 2021 "Dirty Dozen of Latin America" retrospective + January 2024 Grandoreiro disruption Mekotio operator-relation discovery)Check Point Research (canonical November 2021 evolved variant disclosure, Arie Olshtein + Abedalla Hadra + Kobi Eisenkraft Team Leader)Trend Micro Research (canonical July 2024 renewed warning + Mekotio Banking Trojan Threatens Financial Systems analysis)Spanish National Police / Spanish Civil Guard (canonical July 2021 arrest of 16 distribution-network individuals)Kaspersky GReAT (Tetrade framework cross-reference + Mekotio = Melcoz consideration per some research)CyberScoop (canonical industry reporting)The Hacker News (canonical Trend Micro July 2024 industry coverage)SC Media (canonical industry coverage)Tempest (Latin American banking trojan tracking)Global Security Mag (canonical LATAM Banking Trojan Mekotio coverage)RedPacket Security (canonical Mekotio industry coverage)CIRT.GY Guyana National CIRT (canonical regional advisory coverage)Scitum (Mexico, Latin American banking trojan tracking)MITRE ATT&CK Software S1015 (Mekotio)Malpedia Software Profile (Mekotio)
Key reporting
reportESET WeLiveSecurity: August 2020 canonical Mekotio first documentation + December 2021 'Dirty Dozen of Latin America: From Amavaldo to Zumanek' retrospective + January 2024 Grandoreiro disruption Mekotio operator-relation discovery
reportCheck Point Research (Arie Olshtein + Abedalla Hadra + Kobi Eisenkraft): canonical November 2021 evolved variant disclosure with substitution cipher + Themida packer analysis
reportTrend Micro Research: Mekotio Banking Trojan Threatens Financial Systems in Latin America (July 4, 2024), canonical 2024 renewed warning
reportSpanish National Police / Spanish Civil Guard: canonical July 2021 arrest of 16 distribution-network individuals
reportKaspersky GReAT: Tetrade framework cross-reference (Mekotio = Melcoz consideration per some research)
reportCyberScoop: Potent Brazilian banking trojan resurfaces in South America (2021)
reportThe Hacker News: Experts Warn of Mekotio Banking Trojan Targeting Latin American Countries (July 2024) + Mekotio Banking Trojan Resurfaces With New Attacking and Evading Techniques (November 2021)
reportSC Media: canonical industry coverage
reportTempest: Latin American banking trojan tracking
reportGlobal Security Mag: LATAM Banking Trojan Mekotio Returns in Stronger Form (November 2021)
reportRedPacket Security: canonical Mekotio industry coverage
reportCIRT.GY Guyana National CIRT: canonical regional advisory coverage
reportScitum (Mexico): Red Mongoose Daemon adjacent Latin American banking trojan disclosure (July 2024)
reportMITRE ATT&CK Software S1015: Mekotio
reportMalpedia Software Profile: Mekotio

Operational

State sponsor

Brazilian-origin organized cybercrime, Latin American banking trojan operator group with close collaboration with European distribution gangs. Operationally separate from state-sponsored APT activity. Attribution chain: (1) ESET canonical August 2020 first documentation: ESET WeLiveSecurity published canonical Mekotio analysis establishing Brazilian-origin attribution + Latin American banking trojan classification. Per ESET (via The Hacker News): "Mekotio shares common characteristics for this type of malware, such as being written in Delphi, using fake pop-up windows, containing backdoor functionality and targeting Spanish-and Portuguese-speaking countries." (2) Spanish Civil Guard canonical July 2021 joint arrest: Spanish law enforcement agencies arrested 16 individuals belonging to criminal network in connection with orchestrating social engineering campaigns targeting European users that delivered Grandoreiro and Mekotio. Per ESET December 2021 "Dirty Dozen of Latin America" retrospective: nearly €300,000 stolen + €3.5M attempted transfer blocked. ESET assessed Mekotio took larger hit than Grandoreiro per telemetry, believed arrested people more connected to Mekotio than Grandoreiro. (3) Check Point Research canonical November 2021 evolved variant disclosure: per Check Point Research (Arie Olshtein + Abedalla Hadra) + CPR Malware Research Team Leader Kobi Eisenkraft: "Although the Spanish Civil Guard announced the arrest of 16 people involved with Mekotio distribution in July 2021, it appears the gang behind the malware is still active." CPR detected + blocked 100+ post-arrest attacks targeting Brazil + Chile + Mexico + Spain + Peru with new substitution cipher obfuscation + Themida packer evasion. Per Check Point: "the threat actors behind Mekotio... operates from Brazil and collaborates with European gangs to distribute the malware." (4) Trend Micro canonical July 2024 renewed warning: Trend Micro Research published canonical "Mekotio Banking Trojan Threatens Financial Systems in Latin America" analysis identifying recent attack surge + persistent threat to Latin American financial systems. Per Trend Micro: "The Mekotio banking trojan is a sophisticated piece of malware that has been active since at least 2015, primarily targeting Latin American countries with the goal of stealing sensitive information, particularly banking credentials, from its targets." (5) ESET January 2024 Grandoreiro disruption Mekotio operator-relation discovery: per ESET ETeC 2024: "After sharing the data about C&C servers with ESET partners in the private and government sectors, law enforcement authorities not only disrupted Grandoreiro but, during their analysis of the seized materials, police were able to link the Grandoreiro perpetrators to old cases they investigated, related to other criminal activity. They also discovered that one of the arrested suspects had very close relations with Mekotio, another infamous LATAM banking trojan." Cluster-cell coherence with Grandoreiro cluster established via shared operator network. (6) Kaspersky Tetrade framework cross-reference (Mekotio = Melcoz consideration): per CyberScoop + The Hacker News: "Researchers with Kaspersky grouped Mekotio (also known as 'Melcoz') into a larger group they called Tetrade." Some industry research treats Mekotio + Melcoz as same family.

ESET treats Mekotio as distinct from Kaspersky Tetrade four-family framework (Guildma + Javali + Melcoz + Grandoreiro). Operational mission objective: Banking credential theft via fake banking site pop-up overlays + remote command + control for direct account access + sensitive information collection. Per Trend Micro: "Mekotio's main goal is to steal banking credentials. It achieves this by displaying fake pop-ups that mimic legitimate banking sites, tricking users into entering their details, which the trojan then proceeds to harvest. Information Gathering: Mekotio can capture screenshots, log keystrokes, and steal clipboard data. Persistence Mechanisms: Mekotio employs various tactics to maintain its presence on the infected system, including adding itself to startup programs or creating scheduled tasks. The stolen banking information is sent back to the C&C server, where it can be further used by malicious actors for fraudulent activities, such as unauthorized access to bank accounts." The cluster fills the most-sustained-Spanish- Portuguese-targeting position in Latin American banking trojan operators cell.

Motivations
banking_credential_theft_spanish_portuguese_speaking_countries, sustained_latin_american_targeting_capability_demonstration, persistent_post_arrest_evolution_capability_demonstration, delphi_based_banking_trojan_classic_brazilian_tradecraft, brazilian_operator_european_distribution_gang_collaboration_model, fake_banking_pop_up_overlay_credential_capture_signature, substitution_cipher_themida_packer_evasion_capability, close_operator_relations_with_grandoreiro_per_eset_january_2024
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)55/60 · 91%
Analytics (MITRE CAR)26/60 · 43%
Runtime / container (Falco)6/60 · 10%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)15/60 · 25%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

0 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MEKOTIO MELCOZ ALTERNATIVE NAMING PER KASPERSKYMEKOTIO MALWAREMICROSOFT AZURE CLOUD ENVIRONMENTS FILE HOSTINGMODULAR DESIGN CHANGEABLE PARTS FOR DETECTION AVOIDANCEMSI INSTALLER PAYLOAD DELIVERYMULTI STAGE DELIVERY INFRASTRUCTURE FOR DETECTION AVOIDANCESCHEDULED TASKS PERSISTENCESCREENSHOT KEYLOGGER CLIPBOARD DATA COLLECTIONSPOOFED EMAIL DIGITAL TAX RECEIPT PENDING SUBMISSIONSUBSTITUTION CIPHER OBFUSCATION
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin