A malware strain known as Coyote has been observed abusing the Windows UI Automation framework, a legitimate accessibility feature, to read on-screen banking information and steal credentials without triggering typical security alerts.
Key Takeaways
- ✔Coyote malware abuses Windows UI Automation, a legitimate accessibility API, to read sensitive on-screen data
- ✔The technique lets the malware identify banking applications and extract credentials without traditional keylogging
- ✔Because UI Automation is a legitimate Windows feature, this behavior can evade some traditional detection methods
- ✔Endpoint detection tools that monitor for abnormal API usage are better positioned to catch this technique
What Makes This Technique Different
Most credential-stealing malware relies on keylogging or fake login overlays. Coyote instead uses the Windows UI Automation framework, designed to help accessibility tools read screen content, to identify banking application windows and extract sensitive information directly, without needing to intercept keystrokes.
Why Traditional Defenses Can Miss It
Because UI Automation is a legitimate, signed Windows component, security tools that only flag known-malicious binaries or behaviors can miss this abuse pattern. Detection increasingly depends on monitoring how legitimate APIs are being used, not just what software is running.
Defending Against the Technique
Endpoint detection and response tools that baseline normal application behavior are better equipped to flag unusual UI Automation activity. Employee awareness about phishing delivery vectors also remains important, since Coyote and similar malware still typically arrive through a malicious download or attachment.
Sources
- ✔Security research coverage of the Coyote banking trojan
Ready to Strengthen Your IT and Security?
BetterWorld Technology partners with organizations nationwide to deliver managed IT, cybersecurity, and compliance services built around your business goals.