Dangerous Horabot Malware Sweeps Latin America: Invoice Scam Steals Credentials and Deploys Banking Trojans


# New Horabot Malware Campaign Targets Latin American Windows Users

Cybersecurity researchers have uncovered a sophisticated phishing campaign distributing Horabot malware across Latin America, primarily affecting users in Mexico, Guatemala, Colombia, Peru, Chile, and Argentina.

The campaign, detected by Fortinet FortiGuard Labs in April 2025, uses deceptive emails that mimic invoices and financial documents to trick Spanish-speaking victims into opening malicious attachments. Once infected, the malware can steal email credentials, harvest contact lists, and deploy banking trojans.

Particularly concerning is the malware’s ability to propagate through victims’ email accounts using Outlook COM automation, allowing it to spread laterally within corporate and personal networks. The threat actors employ various scripts (VBScript, AutoIt, and PowerShell) to perform system reconnaissance, credential theft, and deliver additional payloads.

First documented by Cisco Talos in June 2023, Horabot has targeted Spanish-speaking users since at least November 2020, with evidence suggesting Brazilian threat actors are behind the attacks. Trustwave SpiderLabs identified similar campaigns in the region last year.

The infection chain begins with invoice-themed phishing emails containing ZIP archives. These archives hold HTML files with Base64-encoded data that connect to remote servers to download additional payloads, including HTML Applications that execute remote scripts. The malware performs environment checks, avoiding systems with Avast antivirus or virtual environments.

Once established, Horabot collects system information, steals browser data from multiple browsers (including Brave, Chrome, Edge, and Opera), and monitors user behavior. It also injects fake pop-up windows designed to capture login credentials.

Share This Article