Researchers reported that the Coyote banking trojan is actively targeting users, primarily in Brazil, through a multi-stage infection chain that begins with malicious Windows .lnk shortcut files. The shortcuts launch PowerShell, which in turn deploys shellcode, performs DLL-based process injection, and uses Donut-assisted payload execution before installing a final MSIL payload with registry-based persistence. Once running, Coyote conducts anti-analysis checks, fingerprints the host, communicates with command-and-control infrastructure over port 443, and supports a broad set of capabilities including keylogging, screenshots, phishing overlays, clipboard abuse, window manipulation, remote control actions, and system shutdown.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
FortiGuard Labs reported identifying several similar malicious Windows LNK files over the prior month that were used in multi-stage operations delivering the Coyote Banking Trojan. The campaign targeted Windows users in Brazil and used PowerShell, shellcode, DLL injection, and registry persistence.
Akamai documented that Coyote checks active window titles and, when needed, abuses Windows UI Automation to inspect browser tabs and address bars for targeted banks and cryptocurrency exchanges. The research characterized this as the first observed malware using UI Automation in the wild for this purpose and included detection ideas involving uiautomationcore.dll and UIA-related named pipes.
Fortinet published technical details showing that this Coyote version targeted 1,030 sites and 73 financial agents, expanding beyond earlier targeting. The report also described its credential theft, keylogging, screenshot capture, phishing overlays, remote-control commands, and C2 infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 53 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.