Coyote is a Brazil-focused Windows banking trojan first publicly reported in 2024. It targets online banking and cryptocurrency services and has expanded from targeting dozens of Brazilian financial websites to more than a thousand sites by early 2025. The malware is associated with campaigns aimed primarily at Brazilian users and has been discussed alongside other Brazilian banking malware families such as Grandoreiro, Mekotio, and Maverick, with later research noting code and tradecraft overlap between Coyote and Maverick.
Coyote uses a multi-stage infection chain and has been observed distributed as a fake or trojanized Windows application updater built with the Squirrel installer framework. Reported delivery chains include Node.js/Electron components running obfuscated JavaScript, DLL sideloading, and a Nim-based loader that unpacks and executes a final .NET payload in memory. Later campaigns linked to related activity also used malicious shortcut files and multi-stage PowerShell execution. Persistence has been achieved through Windows logon-script abuse and reuse of legitimate-looking components across reboots.
Once active, Coyote profiles the infected host and sends victim metadata to command-and-control infrastructure, including system identity details and information about which financial services the victim uses. It monitors active applications and browser activity for targeted banking and cryptocurrency services. A notable evolution is its abuse of Microsoft Windows UI Automation to inspect foreground windows and browser interface elements such as tabs and address bars when simple window-title matching is insufficient. This enabled more reliable identification of targeted financial sessions and is widely noted as the first confirmed malicious use of Windows UI Automation in the wild for banking credential theft.
Coyote supports core banking-trojan functions including credential harvesting through phishing overlays, keylogging, screenshot capture, process termination, cursor manipulation, fake update or lock-screen style blocking, and host shutdown. Its objective is to steal banking credentials and facilitate fraudulent transactions against desktop banking users. Telemetry and reporting indicate infections have been concentrated overwhelmingly in Brazil.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
The target field of the LNK file contained an obfuscated Windows command that constructed and ran an initial Base64-encoded PowerShell command.
The campaign ... seeks to trick users into executing a malicious file attached to a self-spreading message received from a previously infected WhatsApp web session. | The archive contained a malicious Windows LNK file that, when launched, initiated a series of malicious PowerShell commands.
The target field of the LNK file contained an obfuscated Windows command that constructed and ran an initial Base64-encoded PowerShell command.
“It then runs a signed application from that directory… Several executables have been identified in use, including those associated with Chrome and OBS Studio.”
Coyote invokes the GetForegroundWindow() Windows API to obtain a handle to the currently active window. Once it retrieves the window handle, the malware will compare the window title to a list of hardcoded web addresses belonging to targeted banks and crypto exchanges.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Brazilian banking malware noted in 2025 as an active family involved in credential theft and fraudulent desktop banking transactions.
Referenced as an established Latin American banking trojan with similar behaviors (e.g., overlay logic, active window monitoring, LNK hijacking) to VENON.
Banking malware referenced as similar to Maverick; targets Brazilian users/banks.
Windows banking trojan variant abusing Windows UI Automation to steal banking/crypto credentials; targets Brazilian users (per summary).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.