Coyote Banking Trojan First to Abuse Microsoft UIA

Threat Score
66%
7 articles 100.0% Similarity 2 days ago

Activity Timeline

Coyote malware abuses Windows accessibility framew...
BleepingComputer
Jul 22
17:54
Coyote Trojan First to Use Microsoft UI Automation...
Hackread
Jul 22
21:50
Coyote Malware Targets WILS, Abusing Microsoft UI ...
GB Hackers
Jul 23
09:27
Coyote Banking Trojan First to Abuse Microsoft UIA...
SecurityWeek
Primary Article
Jul 23
12:05
New Coyote Malware Variant Exploits Windows UI Aut...
The Hacker News
Jul 23
12:58
Coyote Malware Abuses Microsoft’s UI Automation in...
Cybersecurity News
Jul 23
13:51
Banking Trojan Coyote Abuses Windows UI Automation...
Dark Reading
Jul 23
21:29
  • Coyote banking trojan is the first malware to exploit Microsoft's UI Automation (UIA) framework, targeting Brazilian users and stealing credentials from 75 banking and cryptocurrency sites.
  • The malware can log keystrokes, capture screenshots, and overlay login pages, enhancing its stealth and effectiveness in credential theft.
  • Akamai researchers initially identified the potential for UIA abuse in December 2024, with active exploitation confirmed in 2025.
  • No specific CVEs have been reported, but organizations should be aware of the risk posed by the UIA framework in their environments.
  • Immediate actions include monitoring for unusual UI interactions, educating users on phishing tactics, and implementing endpoint protection solutions.

The Coyote banking trojan has emerged as a significant threat by exploiting Microsoft's UI Automation (UIA) framework to harvest login credentials from Brazilian banking and cryptocurrency platforms. This malware employs advanced techniques like keystroke logging and UI overlays, making it particularly dangerous. Organizations must be vigilant, as there are currently no patches available for the UIA framework. Security teams should focus on monitoring user interface interactions, enhancing user education on phishing risks, and deploying robust endpoint protection measures to mitigate this evolving threat.

Save to Folder

Choose a folder to save this cluster: