Melcoz
Melcoz (canonical Kaspersky Tetrade framework naming per Securelist July 14, 2020 disclosure by Fabio Assolini "The Tetrade: Brazilian banking malware goes global".
sometimes equated with Mekotio per industry naming dispute reported by CyberScoop + The Hacker News "Researchers with Kaspersky grouped Mekotio also known as Melcoz into a larger group they called Tetrade", naming convention dispute between Kaspersky treating Mekotio = Melcoz Tetrade family member + ESET treating Mekotio as distinct) is a Brazilian-origin banking trojan derived from Remote Access PC open-source RAT lineage, active since at least 2018 (group active in Brazil for years prior to 2018 international expansion)
Brazilian-origin organized cybercrime attribution via Kaspersky Tetrade framework canonical classification alongside Guildma + Javali + Grandoreiro four major Brazilian banking trojan families (curated as Melcoz distinct per Kaspersky 2020 framework + acknowledges Mekotio overlap)
standalone malware platform cluster paralleling javali + mispadu + casbaneiro in v0.1.139 LATAM banking trojan operators cell expansion; operational target profile Brazil + Chile (since 2018 first international target post-Brazil per Kaspersky "the group has attacked assets in Chile since 2018") + Mexico (more recent expansion per Kaspersky 2020) + Spain expansion + Latin America broadly.
operational attack architecture: (1) phishing emails with MSI installer links.
(2) cluster-defining two delivery techniques per Kaspersky, AutoIt loader script + DLL hijacking ("Kaspersky identified two techniques for the malware's delivery, namely an AutoIt loader script and DLL hijacking")
(3) VBS scripts in installer package files per IT Pro.
(4) cluster-defining password theft from memory + browser dual-source ("steals passwords from a user's memory and browser" per Kaspersky + IT Pro)
(5) cluster-defining Bitcoin wallet clipboard replacement hijack tradecraft ("It can also steal a user's Bitcoin wallet and replace the user's wallet information with hacker's banking information" per Kaspersky) cluster-cell coherent with v0.1.133 grandoreiro.yaml crypto wallet replacer + Casbaneiro Bitcoin wallet clipboard tradecraft.
(6) fake banking pop-up overlay GUI input capture typical LATAM banking trojan tradecraft.
(7) cluster-defining Eastern European partner collaboration model per Kaspersky ("Their Eastern European partners heavily inspired the recent attacks. The new operations are professionally executed, scalable and persistent, creating various versions of the malware, with significant infrastructure improvements that enable cybercriminal groups in different countries to collaborate"), signature Brazilian-Eastern-European cybercriminal collaboration model.
(8) cluster-defining Remote Access PC open-source RAT lineage per Kaspersky + SecurityWeek + IT Pro, distinct lineage from typical LATAM banking trojan codebases ("A variant of Remote Access PC, an open-source remote access Trojan")
(9) Delphi programming language origin signature typical LATAM banking trojan codebase.
cluster fills the Remote-Access-PC-RAT-lineage + Bitcoin-wallet- clipboard-hijack + Eastern-European-partner- collaboration position in Latin American banking trojan operators cell + completes Kaspersky Tetrade framework standalone curation (Guildma + Javali + Melcoz + Grandoreiro)
canonical illustration of Kaspersky Tetrade framework member + Remote Access PC RAT open-source lineage + Bitcoin wallet clipboard hijack + Eastern European partner collaboration model tradecraft cited in essentially all subsequent Latin American banking trojan industry analyses through 2018-2026 period.