Melcoz

S0530

Malware.View on attack.mitre.org

About this malware

Melcoz is a banking trojan family built from the open source tool Remote Access PC. Melcoz was first observed in attacks in Brazil and since 2018 has spread to Chile, Mexico, Spain, and Portugal.

Techniques used12

Procedure examples12

TechniqueProcedure example
T1027.002
Software Packing

Melcoz has been packed with VMProtect and Themida.

T1059.005
Visual Basic

Melcoz can use VBS scripts to execute malicious DLLs.

T1059.010
AutoHotKey & AutoIT

Melcoz has been distributed through an AutoIt loader script.

T1105
Ingress Tool Transfer

Melcoz has the ability to download additional files to a compromised host.

T1115
Clipboard Data

Melcoz can monitor content saved to the clipboard.

T1185
Browser Session Hijacking

Melcoz can monitor the victim's browser for online banking sessions and display an overlay window to manipulate the session in the background.

T1204.001
Malicious Link

Melcoz has gained execution through victims opening malicious links.

T1218.007
Msiexec

Melcoz can use MSI files with embedded VBScript for execution.

T1555.003
Credentials from Web Browsers

Melcoz has the ability to steal credentials from web browsers.

T1565.002
Transmitted Data Manipulation

Melcoz can monitor the clipboard for cryptocurrency addresses and change the intended address to one controlled by the adversary.

T1566.002
Spearphishing Link

Melcoz has been spread through malicious links embedded in e-mails.

T1574.001
DLL

Melcoz can use DLL hijacking to bypass security controls.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. Securelist Brazilian Banking Malware July 2020 Open source
    GReAT. (2020, July 14). The Tetrade: Brazilian banking malware goes global. Retrieved November 9, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.