Skip to content
The SOC Files: Time to “Sapecar”. Unpacking a new Horabot campaign in Mexico

The SOC Files: Time to “Sapecar”. Unpacking a new Horabot campaign in Mexico

Securelist Domenico Caldarella, Mateus Salgado March 18, 2026

In this installment of our SOC Files series, we will walk you through a targeted campaign that our MDR team identified and hunted down a few months ago. It involves a threat known as Horabot , a bundle consisting of an infamous banking Trojan, an email spreader, and a notably complex attack chain.

Although research has documented Horabot campaigns ( here and here ), our goal is to highlight how active this threat remains and to some aspects not covered in those analyses.

As usual, our story begins with an alert that popped up in one of our customers’ environments. The rule that triggered it is generic yet effective at detecting suspicious mshta activity. The case progressed from that initial alert, but fortunately ended on a positive note. Kaspersky Endpoint Security intervened, terminated the malicious process (via a proactive defense module ( PDM )) and removed the related files before the threat could progress any further.

Extracted Entities

Attack Types (1)

Campaigns (1)

Countries (1)

Malware (1)

MITRE ATT&CK (1)

Tools (1)