Dark Tequila

Description

(Kaspersky) Dark Tequila is a complex malicious campaign targeting Mexican users, with the primary purpose of stealing financial information, as well as login credentials to popular websites that range from code versioning repositories to public file storage accounts and domain registrars.

A multi-stage payload is delivered to the victim only when certain conditions are met; avoiding infection when security suites are installed or the sample is being run in an analysis environment. From the target list retrieved from the final payload, this particular campaign targets customers of several Mexican banking institutions and contains some comments embedded in the code written in the Spanish language, using words only spoken in Latin America.

Names

Name
Dark Tequila
DarkTequila

Category

Malware

Type

  • Banking trojan
  • Backdoor
  • Info stealer
  • Credential stealer

Information

Malpedia

Other Information

Uuid

8364f12b-27c5-43a2-aa98-79ae79e92c8f

Last Card Change

2022-12-28