typeconceptconfidencehighcreated2026-08-07updated2026-08-07banking-trojansynthetic-inputsendinputmousekeyboardlatam

synthetic-input-manipulation

Cross-family concept for banking trojans that use SendInput, mouse_event, keybd_event, or Windows hooks to inject synthetic input and manipulate online banking sessions.

Pattern

  1. Mouse injection: SendInput with tagMOUSEINPUT to click attacker-controlled UI elements.
  2. Keyboard injection: SendInput with tagKEYBDINPUT to type attacker-controlled values (e.g., transfer amounts, recipient names).
  3. Cursor positioning: SetCursorPos to move the pointer to specific screen coordinates.
  4. Window targeting: FindWindowW / EnumWindows / GetForegroundWindow to identify the browser window, then GetWindowTextW to confirm the banking site.

Observed Implementations

  • bromechokucom (36a4bca2) imports SendInput, SetCursorPos, GetCursorPos, and carries tagMOUSEINPUT / tagKEYBDINPUT / tagINPUT strings alongside TValorClickHelper for value-based click manipulation ^[/intel/analyses/36a4bca295060d1d96f7ac3c65462f581823d74cd4cceac9ae5b3f660341de9a.html].

Related