BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Greedy Sponge Group Deploys Modified AllaKore RAT in Mexico

Greedy Sponge Continues Targeted Cyberattacks on Mexican Organizations Using Advanced Malware and Evasion Techniques

  • Mexican organizations continue to face threats from a Hacking group named Greedy Sponge, which uses modified Malware in targeted attacks.
  • The group deploys a customized AllaKore RAT and SystemBC to steal banking credentials and support financial fraud.
  • Attacks are carried out using phishing emails and compromised websites, leading to malicious ZIP files that infect targets.
  • Recent campaigns use advanced measures like regional access restrictions and proxy malware to hide activities and block analysis.
  • Other malware threats, such as PureRAT and Neptune RAT, also use creative techniques like encrypted payloads and process injection to bypass security measures.

Mexican businesses and government sectors have been targeted since 2021 by a financially driven hacking group known as Greedy Sponge. The group carries out cyberattacks using modified versions of AllaKore RAT and SystemBC malware, aiming to steal banking credentials and conduct fraud.

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading

According to Arctic Wolf Labs, these attacks focus on a broad range of sectors, including retail, manufacturing, public services, and banking. The AllaKore RAT has been heavily changed to send specific banking data and authentication information to servers controlled by the attackers. “The AllaKore RAT payload has been heavily modified to enable the threat actors to send select banking credentials and unique authentication information back to their command-and-control (C2) server, for the purpose of conducting financial fraud,” Arctic Wolf stated in a recent analysis.

Initial infection commonly starts through targeted phishing emails or drive-by website attacks that distribute infected ZIP archives. Inside are legitimate-looking files alongside a disguised installer, which drops the AllaKore RAT. The malware allows remote control and capability to log keystrokes, take screenshots, and download or upload files. Attackers also use SystemBC, which can turn infected machines into proxies, hiding command and control (C2) traffic by routing it through SOCKS5 proxies. Updated tactics now restrict the final malware delivery to users located in Mexico using server-side checks, making it harder for outside analysts to study the campaign.

< b >Greedy Sponge< /b > has been using similar tools and infrastructure for over four years, with focused attacks in Mexico. Other regions, such as Brazil, have also experienced campaigns using AllaKore variants. Arctic Wolf described the group as persistent and successful, but not highly advanced.

Recent months have shown other related cybercrime techniques. In one campaign, a phishing attack used a new crypter, Ghost Crypt, to encrypt and deliver PureRAT malware. Attackers used urgent phone calls and PDF files with links to malicious content to trick victims. Ghost Crypt, first advertised in April 2025, helps attackers avoid detection by Microsoft Defender and delivers various types of malware, such as Lumma and StealC.

- Advertisement -

Other ongoing threats include Neptune RAT, spread by JavaScript-based lures, and attacks using malicious Inno Setup installers, which run scripts to install information-stealing malware like RedLine. These approaches use automated scripts and layered payloads to bypass traditional security controls.

For more technical analysis and information on tactics, readers can refer to the detailed articles by Arctic Wolf Labs, Arctic Wolf, eSentire, and Splunk Threat Research Team.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Alphabet Pays First 2026 Dividend, Starts “Snowball” Effect

Alphabet Inc. (GOOGL) paid its first quarterly dividend for 2026 on March 16.The dividend...

Bitcoin Mining Difficulty Plunges 7.7%

Bitcoin’s mining difficulty plunged 7.7% to 133.79 trillion on March 20, its sharpest decline...

TeamPCP Worm Spreads to npm Via Blockchain C2

Hackers linked to the TeamPCP operation have unleashed a self-propagating malware worm called CanisterWorm...

Early Ethereum Whale Buys $19.5M ETH as Market Eyes Thaw

The wallet known as thomasg.eth purchased approximately $19.5 million in Ethereum over the past...

CISA Flags 5 Exploited Flaws in Apple, CMS

The U.S. CISA has added five actively exploited security flaws impacting Apple, Craft CMS,...

Must Read

TOP 12 Day Trading Crypto Books For Beginners

Day trading cryptocurrencies has become an increasingly popular financial activity, offering the potential for huge returns to those who understand the market's complexities and...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading