DCRat Targets Latin American Users to Steal Banking Credentials
IBM X-Force has identified a series of targeted email campaigns initiated by Hive0131, a financially motivated threat group likely originating from South America.
IBM X-Force has identified a series of targeted email campaigns initiated by Hive0131, a financially motivated threat group likely originating from South America.
In early May 2025, these campaigns targeted users in Colombia, posing as official communications from The Judiciary of Colombia, particularly the Civil Circuit of Bogota.
The objective of these attacks is to deploy the banking trojan DCRat, a Malware-as-a-Service (MaaS) tool known for its affordability and prevalence in the region since at least 2024.
DCRat is priced at USD 7 for a two-month subscription and is heavily marketed on Russian cybercrime forums since 2018. It is widely used for stealing sensitive banking credentials and other personal information.
Hive0131's Latest Phishing Campaign in Colombia
Hive0131 employs sophisticated infection chains designed to evade detection and deceive victims into executing malicious payloads.
One method involves phishing emails with PDF attachments containing embedded TinyURL links. Clicking these links redirects users to a ZIP archive containing a malicious JavaScript file, which fetches additional payloads from paste[.]ee sites.
This process executes a PowerShell command to download a disguised JPG file with a base64-encoded loader, named VMDetectLoader by X-Force, which deploys DCRat directly in memory.
Another vector uses emails with embedded Google Docs links leading to password-protected ZIP files containing batch file downloaders.
DCRat is priced at USD 7 for a two-month subscription and is heavily marketed on Russian cybercrime forums since 2018.
These downloaders retrieve obfuscated VBScripts and PowerShell scripts, culminating in the execution of the VMDetectLoader, which then deploys the trojan.
VMDetectLoader, based on the open-source VMDetector project, incorporates anti-analysis features to detect virtual machines and sandbox environments, ensuring it operates only on genuine victim systems.
DCRat is a significant threat, capable of bypassing Windows’ Antimalware Scan Interface (AMSI), terminating blocklisted processes, and establishing persistence through scheduled tasks or registry keys.
Its plugins facilitate keylogging, clipboard data theft, file encryption, and audio or video recording of victims. Once operational, it connects to a command-and-control (C2) server to receive instructions, often targeting banking credentials for financial gain.
IBM X-Force reports that while Hive0131 has used other malware like QuasarRAT and NjRAT, the shift to DCRat in recent campaigns indicates an evolving threat landscape in Latin America, where phishing remains a common attack vector.
Organizations in the region are advised to enhance their defenses by scrutinizing emails with links or attachments, monitoring for signs of process injection or unauthorized scheduled tasks, and ensuring robust endpoint security configurations to mitigate such threats.
Indicator Indicator Type Context
4ce1d456fa8831733ac01c4a2a32044b6581664d311b8791bb2efaa2a1d01f17 SHA256 Carrier File
1603c606d62e7794da09c51ca7f321bb5550449165b4fe81153020021cbce140 SHA256 DCRat
0df13fd42fb4a4374981474ea87895a3830eddcc7f3bd494e76acd604c4004f7 SHA256 Obfuscated .NET Loader
hxxps://tinyurl[.]com/2ypy4jrz?id=5541213d-0ed8-4516-82e7-5460d4ebaf3b URL Embedded PDF Link
hxxps://archive[.]org/download/new_ABBAS/new_ABBAS.jpg URL JPG Download URL
Based on reporting by GBHackers.
