Melcoz is a Brazilian banking trojan associated with the Latin American banking malware cluster known as the Tétrade, alongside Guildma, Javali, and Grandoreiro. It has been observed expanding beyond Latin America into other regions, including Europe, as part of the broader internationalization of Brazilian banking malware operations. Melcoz is written in Delphi and is focused on financial fraud and credential theft against online banking users on Windows systems.
Melcoz is capable of stealing credentials stored in web browsers and monitoring browser activity during online banking sessions. It can display overlay windows to manipulate the victim’s banking session in the background, a behavior consistent with banking trojans that interfere with live transactions and harvest sensitive information. The malware can also monitor clipboard contents, supporting theft of user data and potentially facilitating fraud workflows.
For execution and defense evasion, Melcoz has been observed using DLL hijacking and malicious DLL execution via VBScript or VBS-based components. Reported delivery and staging mechanisms include malicious links embedded in emails, MSI packages containing embedded VBScript, and AutoIt-based loader scripts. Samples have also been protected with commercial packers including VMProtect and Themida to hinder analysis and detection.
Melcoz is part of the Brazilian banking trojan ecosystem that has historically relied on social engineering and modular execution chains to infect victims and compromise banking activity. Its tradecraft reflects the broader evolution of Brazilian financial malware toward more flexible delivery, stronger evasion, and cross-region targeting.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
Multiple actors and malware families are described as sending spearphishing/phishing emails containing malicious links (including shortened URLs, cloud-hosted links, and links to archives or documents) to deliver malware, harvest credentials, or redirect victims to malicious content.
APT-C-36 has embedded a VBScript within a malicious Word document which is executed upon the document opening.
APT39 has utilized AutoIt and custom scripts to perform internal reconnaissance. Melcoz has been distributed through an AutoIt loader script.
Denis exploits a security vulnerability to load a fake DLL and execute its code. Empire contains modules that can discover and exploit various DLL hijacking opportunities. PowerSploit contains a collection of Privesc-PowerUp modules that can discover and exploit DLL hijacking opportunities in services and processes.
"AppleJeus ... has also used DLL search order hijacking via the IKEEXT service, running with LocalSystem privileges, to load the TAXHAUL DLL for persistence." / "APT41 ... has used search order hijacking to execute malicious payloads" / "Cinnamon Tempest has used search order hijacking to launch Cobalt Strike Beacons."
"Sandworm Team used UPX to pack a copy of Mimikatz"; "APT38 has used several code packing methods such as Themida, Enigma, VMProtect, and Obsidium"; "Lazarus Group packed malicious .db files with Themida to evade detection."
“AppleJeus delivered components using a Windows Installer package (.msi)… executed the 3CXDesktopApp.exe…”, “APT38 has used msiexec.exe to execute malicious files.”, “Rancor has used msiexec to download and execute malicious installer files over HTTP.”, “TA505 has used msiexec to download and execute malicious Windows Installer files.”
Denis exploits a security vulnerability to load a fake DLL and execute its code. Empire contains modules that can discover and exploit various DLL hijacking opportunities. PowerSploit contains a collection of Privesc-PowerUp modules that can discover and exploit DLL hijacking opportunities in services and processes.
"AppleJeus ... has also used DLL search order hijacking via the IKEEXT service, running with LocalSystem privileges, to load the TAXHAUL DLL for persistence." / "APT41 ... has used search order hijacking to execute malicious payloads" / "Cinnamon Tempest has used search order hijacking to launch Cobalt Strike Beacons."
Agent Tesla can gather credentials from a number of browsers... APT33 has used a variety of publicly available tools like LaZagne to gather credentials... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge... SELECT action_url, username_value, password_value FROM logins; CryptUnprotectData
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
Agent Tesla can steal data from the victim’s clipboard. APT38 used a Trojan called KEYLIME to collect data from the clipboard. APT39 has used tools capable of stealing contents of the clipboard.
Cobalt Strike can perform browser pivoting and inject into a user's browser to inherit cookies, authenticated HTTP sessions, and client SSL certificates. Dridex can perform browser attacks via web injects to steal information such as credentials, certificates, and cookies. Grandoreiro can monitor browser activity for online banking actions and display full-screen overlay images to block user access to the intended site or present additional data fields. IcedID has used web injection attacks to redirect victims to spoofed sites designed to harvest banking and other credentials. Melcoz can monitor the victim's browser for online banking sessions and display an overlay window to manipulate the session in the background. QakBot can use advanced web injects to steal web banking credentials. TrickBot uses web injects and browser redirection to trick the user into providing their login credentials on a fake or modified web page. Ursnif has injected HTML codes into banking sites to steal sensitive online banking information.
28 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as another Latin American banking trojan for comparison/background only.
Named as another Brazilian banking trojan grouped alongside Ousaban under the 'Tetrade' label.
Brazilian banking trojan mentioned as a peer family within the same Tetrade grouping as Ousaban.
Uses VBS scripts to execute malicious DLLs.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.