Mekotio is a Latin American banking trojan active since at least 2015 that primarily targets Windows users in Brazil, Chile, Mexico, Spain, Peru, and Portugal. It is part of the broader Brazilian banking malware ecosystem and has been associated with financially motivated cybercrime operations that expanded from Latin America into Europe, especially Spain. Security reporting has also linked Mekotio activity to criminal distribution and money-laundering networks disrupted by Spanish law enforcement.
Mekotio is typically written in Delphi and is commonly executed through abuse of legitimate interpreters or applications, especially AutoIt and, in some campaigns, AutoHotkey. It is designed to steal online banking credentials and other sensitive information through the characteristic Latin American banker model: monitoring user activity, waiting for access to targeted financial services, and then presenting convincing fake banking pop-up windows or overlays to capture credentials and related data. Reported variants also include broader backdoor functionality such as screenshots, window manipulation, simulated mouse and keyboard input, machine restart, self-update, and restrictions on access to banking websites. Additional observed capabilities include keylogging, theft of browser-stored credentials, clipboard hijacking for cryptocurrency theft, and collection of host security and environment information such as firewall settings, administrative privileges, Windows version, and installed anti-fraud or antimalware products.
Persistence is commonly achieved through Windows Run entries or startup-folder shortcuts. Mekotio operators have used multiple command-and-control discovery methods, including generated domains and ports, and some variants have used unusual backend designs such as SQL-backed control infrastructure. The family shows strong technical and operational overlap with other Latin American banking trojans, especially Casbaneiro, Vadokrist, and Grandoreiro, including shared or highly similar downloaders, scripting components, string-encryption approaches, and distribution chains. These overlaps are widely assessed as evidence of close cooperation among multiple threat actors rather than a single unified malware family.
Distribution is most commonly via phishing or spam campaigns, often using tax, invoice, court, or other administrative lures in Spanish or Portuguese. Infection chains have included ZIP archives, MSI installers, obfuscated batch scripts, JavaScript, VBScript, and PowerShell stages, as well as HTML smuggling in some campaigns. Common execution patterns include DLL side-loading and staged archive delivery, with recent campaigns emphasizing layered obfuscation, in-memory script execution, geofencing, virtualization checks, and packed final payloads to improve stealth and evade analysis. Mekotio remains one of the most prominent and persistent banking trojan families in the Latin American threat landscape.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
More recently, we have also seen this technique deliver the banking Trojan Mekotio... As previously mentioned, this DLL file is attributed to Mekotio, a malware family of banking Trojans typically deployed on Windows systems that have targeted Latin American industries since the latter half of 2016.
41 distinct techniques documented for this family, organized by ATT&CK tactic.
Once the attackers had access to victim bank accounts, they accessed e-banking portals and sent the funds to accounts under their control.
T1047 Windows Management Instrumentation ✅ ❌ ❌ ✅ ❌ ❌ ✅ ✅ ✅ ❌ ❌ ❌
Mekotio is most commonly executed by abusing the legitimate AutoIt interpreter.
The PowerShell script then downloads Mekotio from the corrected URL and installs and executes it.
T1059.003 Command and Scripting Interpreter: Windows Command Shell ❌ ✅ ✅ ❌ ✅ ❌ ✅ ✅ ❌ ✅ ✅ ❌
A simple BAT dropper drops a VBScript downloader and executes it using two command line parameters.
Once the attackers had access to victim bank accounts, they accessed e-banking portals and sent the funds to accounts under their control.
Once the attackers had access to victim bank accounts, they accessed e-banking portals and sent the funds to accounts under their control.
The batch file extracted from the first zip archive has two layers of obfuscation... The first layer of the obfuscation is a simple substitution cipher.
T1027.001 Obfuscated Files or Information: Binary Padding ❌ ✅ ✅ ❌ ❌ ❌ ✅ ❌ ❌ ✅ ❌ ❌
Once the attackers had access to victim bank accounts, they accessed e-banking portals and sent the funds to accounts under their control.
Mekotio is executed by running a legitimate AutoIt interpreter and passing a loader script for it to interpret.
since 2019, the vast majority of these malware families started to utilize Windows Installer (MSI files) as the first stage of the distribution chain
Operators need to react to this situation and manually command the malware to display the fake pop-up window and take control of the victim’s machine
To ease stealing passwords with its keylogging feature, Mekotio disables the “AutoComplete” option in Internet Explorer.
to steal credentials, they tend to use either fake pop-up windows or keyloggers
Once they infect a victim, they stay hidden and wait until users log into e-banking accounts, silently collecting their credentials.
Mekotio discovers various security tools and banking applications based on window names.
Mekotio collects information about the victim's machine, such as firewall status and Windows version.
Mekotio discovers banking protection software based on file system paths.
Next, the script checks if it is running in a virtual machine: it compares the computer model to the strings ‘VMware Virtual Platform’ and ‘Virtual Machine’, and exits if the computer model is one of the above.
Operators need to react to this situation and manually command the malware to display the fake pop-up window and take control of the victim’s machine
To ease stealing passwords with its keylogging feature, Mekotio disables the “AutoComplete” option in Internet Explorer.
to steal credentials, they tend to use either fake pop-up windows or keyloggers
Mekotio’s network protocol in variants not using SQL is based on Remote_Delphi_Access_PC.
The batch script runs a “PowerShell Download Cradles” which downloads and runs a PowerShell script on the memory... Next, a secondary zip file with a random file name is downloaded to the directory.
custom encryption algorithms are favored over established ones
Operators need to react to this situation and manually command the malware to display the fake pop-up window and take control of the victim’s machine
48 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as part of the Brazilian banking trojan ecosystem for comparison with VENON; no additional behavior details are provided in the content.
Referenced as an established Latin American banking trojan with similar behaviors (e.g., overlay logic, active window monitoring, LNK hijacking) to VENON.
Referenced as a known banking trojan family in the Latin American banking trojan ecosystem.
Named as another Latin American banking trojan family that previously shared downloaders with Grandoreiro.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.