Kaspersky's MDR team uncovered an active Horabot campaign targeting Mexico, with over 5,000 victims identified. The attack chain begins with a fake CAPTCHA page using a ClickFix-style lure, progresses through multiple polymorphic VBScript and HTA stages, and ultimately deploys a Delphi banking Trojan (Casbaneiro/Ponteiro) via
Table of contents
IntroductionThe starting pointThe attack chainDetection engineering and threat hunting opportunitiesIoCsSort: