AllaKore RAT Targets Mexican Financial Institutions

A recent spear-phishing campaign has put Mexican financial institutions in its crosshairs, delivering a modified version of the AllaKore RAT, an open-source remote access trojan. The BlackBerry Research and Intelligence Team has traced this activity to an unidentified financially motivated threat actor based in Latin America, active since at least 2021.

The campaign employs lures utilizing Mexican Social Security Institute (IMSS) naming conventions and includes links to seemingly legitimate documents during the installation process. The modified AllaKore RAT payload enables threat actors to transmit stolen banking credentials and unique authentication details to a command-and-control (C2) server, facilitating financial fraud.

The attacks seem tailored to specifically target large companies with gross revenues exceeding $100 million across various sectors such as retail, agriculture, public sector, manufacturing, transportation, commercial services, capital goods, and banking.

AllaKore RAT Infection Chain

The infection process initiates with a ZIP file distributed through either phishing or drive-by compromises. This ZIP file contains an MSI installer file, which deploys a .NET downloader responsible for confirming the victim's Mexican geolocation. Subsequently, the altered AllaKore RAT, a Delphi-based RAT initially identified in 2015, is retrieved.

While AllaKore RAT is described as somewhat basic, it possesses potent capabilities such as keylogging, screen capturing, file upload/download, and remote control of the victim's machine, according to BlackBerry. The threat actor has enhanced the malware by adding functionalities related to banking fraud, targeting Mexican banks and crypto trading platforms. These additions include the ability to launch a reverse shell, extract clipboard content, and fetch and execute additional payloads.

The Latin American connection of the threat actor is evidenced by the use of Mexico Starlink IPs in the campaign and the inclusion of Spanish-language instructions in the modified RAT payload. Moreover, the lures employed are specifically designed for companies of sufficient size to directly report to the Mexican Social Security Institute (IMSS) department.

January 29, 2024
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.