Coyote Trojan Breaks New Ground by Abusing Windows Accessibility Tools!

Listen to this Post

Featured Image
A New Cyber Threat Targeting Banking and Crypto Users in Brazil

In the evolving landscape of cybercrime, attackers are constantly searching for new ways to bypass security and exploit system features for malicious purposes. One such threat, the Windows banking trojan known as Coyote, has emerged as a particularly dangerous strain of malware. First uncovered by Kaspersky in 2024 and now analyzed by Akamai, Coyote has adapted in a shocking new way—by weaponizing Microsoft’s UI Automation (UIA), a feature designed to help people with disabilities, to steal sensitive banking and crypto credentials.

This malware primarily targets Brazilian users and uses UIA to access the graphical user interface (GUI) of Windows apps, harvesting login details from 75 financial institutions and cryptocurrency platforms. What makes this more alarming is that UIA is a legitimate Microsoft framework, often used by screen readers and assistive technologies. Coyote’s misuse of this tool raises serious concerns about the security blind spots in accessibility features.

🧠 Understanding Coyote’s Strategy: How the Malware Works

Coyote is not a newcomer to the malware scene, but its latest technique sets it apart from previous banking trojans. Initially designed to perform basic functions like keylogging, screenshot capture, and overlay injection, the latest version now adopts a more sophisticated mechanism. It scans the foreground window title using the GetForegroundWindow() API to detect whether a user is accessing a target banking or crypto site.

If a match is not found, the malware

By analyzing these elements, Coyote cross-references data with a hard-coded list of 75 financial institutions, a slight increase from the 73 institutions identified in an earlier 2025 report by Fortinet. The use of UIA significantly boosts Coyote’s effectiveness, enabling it to bypass more traditional anti-malware defenses and operate even when offline.

According to Akamai’s research, accessing sub-elements of another application is usually complex unless one possesses deep insight into the application’s structure. UIA simplifies this task dramatically for the malware, offering direct access to UI components across applications—essentially allowing the malware to function like a high-level screen reader with malicious intent.

This strategy mirrors the behavior of many Android banking trojans, which similarly abuse accessibility services to access protected content. The crossover of these techniques from mobile to desktop platforms marks a concerning shift in malware innovation.

🧩 What Undercode Say: Deeper Analysis on the

Coyote’s Abuse of UIA Signals a Dangerous Trend

The use of Microsoft’s UI Automation shows a strategic pivot in malware development—leveraging legitimate OS-level tools to mask malicious behavior. This makes detection significantly harder for antivirus programs that typically monitor for unauthorized or abnormal activity rather than legitimate API usage.

Accessibility Features: A Double-Edged Sword

Accessibility frameworks are essential for users with disabilities, yet their open access nature makes them attractive for exploitation. In Coyote’s case, UIA serves as a stealthy pathway for extracting data, operating behind the scenes without triggering alarms. This highlights the need for better security integration within accessibility tools.

Targeting Brazil: Why This Region?

Brazil has long been a hotspot for banking malware due to its large online banking user base and relatively lax regional cybersecurity policies. Coyote’s laser focus on Brazilian institutions is not surprising. It’s likely that attackers are testing this technique before expanding to other regions.

Offline Functionality: A Scary Advantage

The malware’s ability to perform UI scanning offline is particularly alarming. Many cybersecurity defenses rely on detecting internet-based threats. By removing the need for a live connection, Coyote stays under the radar, possibly even infecting air-gapped systems or users in low-connectivity regions.

From Android to Windows: Cross-Platform Tactics

The adoption of Android-like accessibility abuse tactics in Windows systems could signal a wider trend in future malware strains. As platforms converge in design philosophy, malicious actors are borrowing successful techniques and adapting them cross-platform. This trend should raise red flags for developers, IT professionals, and security analysts alike.

Why Antivirus Alone Won’t Cut It

Standard antivirus solutions are not built to flag legitimate APIs like UIA being used. Malware like Coyote exploits this gap. The industry needs more behavior-based detection, focusing on how programs interact with system elements rather than what APIs they call.

What This Means for Users

End users, especially in Brazil, are at risk of credential theft, financial loss, and compromised crypto wallets. People should be cautious when accessing financial platforms and consider endpoint protection tools that go beyond traditional virus scanning.

Call for Industry-Wide Attention

The cybersecurity community must now rethink how accessibility tools are handled from a security standpoint. Microsoft and others must look into enhanced permission models or user consent layers before granting full UI access to any application, even if it’s using a legitimate API like UIA.

✅ Fact Checker Results

Coyote does abuse

The trojan targets 75 Brazilian financial and crypto platforms — ✅ Verified

UIA was previously demonstrated as a vulnerable pathway in

🔮 Prediction: The Future of Trojan Innovation

Expect to see more malware strains adopting UI automation abuse as a stealthy method to gather data. With attackers proving that accessibility features can be weaponized, there’s a high likelihood that global financial institutions will be targeted next. Additionally, this method may evolve to include ransomware payloads or advanced phishing overlays, further blurring the line between legitimate system tools and malicious activity.

If Microsoft and other OS providers don’t address this soon, Coyote may be just the beginning of a new malware generation—one that hides in plain sight, cloaked in the framework meant to help, not harm.

References:

Reported By: thehackernews.com
Extra Source Hub:
https://www.quora.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin