Free tools Windows power users keep installed
One-click scans. No signup required.
Coyote is a Brazilian banking trojan publicly disclosed by Kaspersky on 8 February 2024. Its original campaign targeted users connected to 61 Brazilian banking institutions and stood out for an unusual delivery chain involving Squirrel, Electron/Node.js, a Nim loader and a .NET payload. Later reports documented new delivery and credential-theft methods, so Coyote is best understood as an evolving malware family—not just one 2024 attack.
What is the Coyote banking trojan?
Coyote is malware designed to steal financial credentials and help attackers interfere with victims’ computers. Kaspersky’s February 2024 disclosure described it as primarily targeting Brazilian users, including people affiliated with more than 60 banking institutions. The figure of 61 institutions in the title comes from The Hacker News’ contemporaneous report of the campaign; it is not a count of confirmed victims.
The malware could watch for activity involving targeted banking applications or websites, then communicate with attacker-controlled infrastructure and carry out commands. Reported capabilities included keystroke logging, screenshots and fake overlays intended to deceive users. Kaspersky researcher Fabio Assolini described Coyote as a new kind of Brazilian banking trojan and urged users to keep defenses current.
How did the original attack chain work?
The 2024 campaign combined several technologies to deliver and run its payload. The stages matter to defenders because activity associated with an installer or script may be an early clue, before the banking-focused behavior becomes visible.
Recommended Free Tools
#1 Best Overall
- Squirrel installer: The initial distribution used Squirrel, an installer framework commonly associated with application updates and installation.
- Electron and Node.js: The installer launched an application built with Electron, which uses Node.js technologies.
- Nim loader: A Nim component unpacked the next-stage payload. Nim is a programming language; its role here was to load malware rather than to carry out the banking theft by itself.
- .NET payload and DLL side-loading: The chain used DLL side-loading to help execute a .NET executable. Side-loading involves a legitimate program loading a malicious DLL in place of, or alongside, an expected component.
- Banking activity monitoring: Once running, Coyote watched for targeted banking applications or websites and could contact attacker-controlled infrastructure.
Kaspersky noted that adding Nim as a loader increased the trojan’s design complexity. For defenders, an uncommon language is not proof of malicious activity; the more useful signal is the combination of an unexpected installer, unusual loader behavior, side-loading and subsequent financial-site activity.
What could Coyote do on an infected computer?
Reported commands covered both credential collection and remote interference. Depending on the command received, Coyote could:
- Log keystrokes and capture screenshots, potentially exposing information entered or displayed during a banking session.
- Show fake overlays that imitate legitimate banking or system interfaces and prompt a user to reveal sensitive information.
- Terminate processes or move the mouse cursor, disrupting the victim’s use of the computer.
- Shut down or lock the machine. A bogus “Working on updates…” message could be displayed while malicious actions continued.
These are reported capabilities, not evidence that every infected computer experienced every action. A fake update screen or an unexpected application closure can have benign causes, so such symptoms should be investigated alongside endpoint and network telemetry.
How did later Coyote activity change?
Reports in 2025 described changes in both delivery and credential collection. Their target counts refer to different research measures—institutions, applications, sites or web addresses—and should not be treated as directly comparable victim totals.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
| Reported activity | Delivery or technique | Reported target scope | Defender clues |
|---|---|---|---|
| Original campaign, disclosed by Kaspersky in February 2024; the 61-institution count was reported by The Hacker News in 2024 | Squirrel installer; Electron/Node.js application; Nim loader; .NET payload; DLL side-loading | 61 Brazilian banking institutions in The Hacker News’ account; Kaspersky described more than 60 | Unexpected installer activity, Nim-based loading, DLL side-loading and suspicious interaction with banking applications or websites |
| FortiGuard Labs report, 30 January 2025 | Malicious Windows shortcut (LNK) files and PowerShell | More than 70 financial applications and a list of 1,030 sites | Unsolicited shortcut files followed by suspicious PowerShell activity; keylogging, screenshots and phishing overlays were also reported |
| CyberProof incident reporting, 12 February 2025 | A suspicious file download through WhatsApp was linked by responders to Coyote activity | Not stated in CyberProof’s incident account | Investigate unexpected messaging-app downloads in context; a file’s arrival through WhatsApp alone does not establish infection |
| Akamai research, 22 July 2025 | A Coyote variant abused Microsoft UI Automation | 75 banking-institute web addresses and cryptocurrency exchanges | Unexpected or unauthorized UI Automation activity associated with financial-site access |
These reports show changes in observed operations, not necessarily a single uninterrupted campaign using every technique. The original target count concerns Brazilian banking institutions; later lists count applications or web addresses and also include cryptocurrency exchanges.
Why is Nim significant?
Nim is significant because Kaspersky identified it as the loader in Coyote’s original chain, between the Electron/Node.js stage and the .NET payload. Using a less commonly encountered language can make a chain less familiar to some defenders and adds another component to investigate. It does not mean Nim software is inherently malicious, or that the later LNK/PowerShell and UI Automation reports used the same Nim-based chain.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How can defenders detect and reduce the risk?
Detection is stronger when teams correlate execution context, process behavior and financial-site activity instead of relying on one filename or technology. The reports support monitoring for the following behaviors:
- Unexpected installers and files: Review unsolicited application installers, Windows shortcut files and attachments or downloads received through messaging apps, especially when they lead to unexpected execution.
- PowerShell and process chains: Investigate PowerShell launched after opening a shortcut or downloaded file, and unusual parent-child process relationships involving installers, Electron/Node.js applications or payload loaders.
- DLL side-loading and loader activity: Look for unexpected DLL loads and a legitimate-looking program loading a component from an unusual location. Assess the executable, DLL, file origin and surrounding process activity together.
- Credential-theft behavior: Alert on suspicious keystroke capture, repeated screenshots, fake interface overlays or unexpected interaction with banking pages and applications.
- UI Automation: Review unauthorized use of Microsoft UI Automation, particularly when it coincides with access to banking or cryptocurrency services.
- Disruptive commands: Treat unexplained process termination, cursor movement, locking or shutdown—especially alongside other suspicious signals—as a reason to investigate the endpoint.
For individual users, avoid opening unexpected installers, shortcuts or messaging attachments, and keep operating-system and security protections updated. If a device shows signs of a possible banking infection, stop using it to enter financial credentials and contact the bank from a separate, trusted device. Organizations should preserve relevant endpoint telemetry and follow their incident-response procedures rather than assuming that a visible symptom alone confirms Coyote.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

