BlackDog is a Mexico-focused banking trojan campaign/family tracked by SCILabs and associated with the threat actor it names Red WinterDog. BlackDog’s primary objective is theft of banking credentials and other sensitive data (including personal information and business email accounts) via Man-in-the-Browser (MitB) activity implemented through malicious browser extensions targeting Google Chrome (and, in the broader Red WinterDog activity set, Microsoft Edge).
Initial access is primarily achieved through malvertising in search engines (notably DuckDuckGo and Bing) using popular Mexico-specific search terms (e.g., CURP, SAT) and through phishing lures impersonating Mexican government entities, especially Servicio de Administración Tributaria (SAT) and Registro Nacional de Población (RENAPO). SCILabs also observed phishing emails posing as invoices and SAT-themed content, with spoofed SAT portals and SAT-related domains used to deliver droppers.
Execution and persistence: BlackDog is installed via malicious JavaScript/HTML and observed infection chains include (1) a June 2022 variant starting from an HTA (e.g., feb.hta) that launches PowerShell and a JSE stage, and (2) an August 2022 variant using a JavaScript dropper (SAT_Policy.js) delivered in a ZIP from a spoofed SAT portal. The chain downloads and installs a malicious Chrome extension (often named “seguridad”), and establishes persistence via scheduled tasks and Windows Startup-folder Chrome shortcut (LNK) files that force-load the extension using the --load-extension parameter. The campaign also used a full-screen lure image displayed via rundll32 as a distraction.
Capabilities: Once loaded in Chrome, the extension injects external JavaScript into visited pages, performs URL checks to identify targeted banking sites, and loads bank-specific scripts that inject fake HTML templates/forms into legitimate banking pages or redirect victims to fake banking sites. Victim-entered credentials and other data are exfiltrated to attacker-controlled infrastructure. SCILabs also observed templates aimed at stealing email credentials. An anti-analysis mechanism was noted where inspecting code in an infected Chrome session triggers an infinite loop that repeatedly enables the debugger and pauses analysis.
Additional observed behavior: In the August 2022 variant, after data entry the victim is prompted to download “asistance” software and redirected to the official TeamViewer site; SCILabs confirmed the TeamViewer binary was legitimate and assessed it was likely used to facilitate follow-on social engineering/remote access.
Activity window and targeting: SCILabs reported Red WinterDog activity predominantly in Mexico from at least June 2022, with last detected activity in May 2023.
Known IOCs explicitly listed in the content include: SHA-256 9A04E1EAA7A98677014D1379D0B972588A98EE0FF62BB70EE97AE26798A0DA92; domains PORTALDECONEXIONSEGURA[.]COM and COMPLEMENTODESEGURIDADMX[.]COM; URL hxxps[:]//drive[.]google[.]com/uc?export=download&id=1U830KFXKJB9XUCTMEGBDCTAPHEVSTENZ; file path %LOCALAPPDATA%\SEGURO.JS; and SAT-spoofing domains kawaitravelmexico[.]com and facturamx[.]club (used to mimic sat[.]gob[.]mx).
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Trojan referenced as being distributed by Red WinterDog using similar droppers/artifacts to those seen in Botnet Fenix/Manipulated Caiman reporting; included as an overlapping ecosystem tool in LATAM campaigns.
Credential-stealing trojan delivered via malicious JS/HTML that installs a malicious Chrome extension to perform man-in-the-browser activity (redirecting to fake banking sites or injecting code into legitimate banking pages) to steal banking and personal information.
Phishing-delivered multi-stage infection chain (HTA/VBS -> PowerShell -> JSE/JS) that installs a malicious Google Chrome extension and persists via Startup LNK shortcuts using the --load-extension parameter. The extension injects external JavaScript into banking sites’ DOM to present fake banking pages and exfiltrate entered credentials/data to attacker infrastructure (MitB). Also observed anti-analysis via forced debugger/infinite loop and a social-engineering step that redirects victims to download legitimate TeamViewer.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.