Operation Tenevoy: How a Sophisticated Trojan Crippled Argentine Businesses in a Massive Financial Heist

In a stark reminder of the escalating threats posed by digital criminal organizations, a sophisticated cyber-fraud network recently targeted dozens of Argentine companies, siphoning off substantial funds through a meticulously executed campaign known as “Operation Tenevoy.” By leveraging a notorious banking Trojan, the criminal syndicate successfully bypassed traditional corporate security measures, laundered the stolen assets through cryptocurrency markets, and funneled the proceeds into a clandestine financial infrastructure.

'Mekotio', el troyano bancario activo en Latinoamérica que con un simple correo de 'importante' engañó a 40 empresas y desató una estafa millonaria

The investigation, which culminated in a series of high-profile arrests, sheds light on the evolving nature of “financial malware” and the vulnerabilities that continue to plague even the most established business environments in Latin America.

'Mekotio', el troyano bancario activo en Latinoamérica que con un simple correo de 'importante' engañó a 40 empresas y desató una estafa millonaria

The Anatomy of the Deception: How the Trap Was Set

The modus operandi of the Tenevoy syndicate relied heavily on social engineering disguised as mundane administrative routine. The attackers targeted employees with emails that appeared to originate from legitimate business partners, suppliers, or government entities. These communications were crafted to mimic standard corporate correspondence, featuring subject lines such as “Pending Invoice,” “Payment Voucher,” or “Urgent Administrative Documentation.”

'Mekotio', el troyano bancario activo en Latinoamérica que con un simple correo de 'importante' engañó a 40 empresas y desató una estafa millonaria

Once an unsuspecting employee opened the attachment—typically an infected document—a silent, malicious payload was deployed. This payload installed Mekotio, a modular banking Trojan that has long been a scourge for financial institutions and businesses across Latin America. Unlike ransomware, which announces its presence by locking files and demanding payment, Mekotio is designed for stealth. It operates in the background, effectively turning the victim’s computer into a window through which the attackers can observe, record, and manipulate financial activity in real time.

'Mekotio', el troyano bancario activo en Latinoamérica que con un simple correo de 'importante' engañó a 40 empresas y desató una estafa millonaria

Chronology of the Attack: From Infiltration to Liquidation

The lifecycle of an attack during Operation Tenevoy followed a precise, multi-stage trajectory designed to maximize theft while minimizing the risk of detection:

'Mekotio', el troyano bancario activo en Latinoamérica que con un simple correo de 'importante' engañó a 40 empresas y desató una estafa millonaria
  1. The Phishing Phase: Attackers deployed bulk email campaigns targeting corporate finance departments. By utilizing high-quality templates and spoofed sender identities, they gained the trust of administrative staff.
  2. Infection and Persistence: Upon the execution of the malicious file, Mekotio established persistence within the system. It gained the ability to monitor the user’s browser activity, specifically targeting banking portals and corporate ERP systems.
  3. Data Exfiltration: The malware captured login credentials, digital certificates, and session tokens. In some instances, it employed “web injects,” displaying fake, pop-up browser windows that mimicked the official websites of banks to trick users into providing multi-factor authentication (MFA) codes.
  4. Unauthorized Transaction Execution: Armed with credentials, the perpetrators accessed the victims’ accounts and initiated fraudulent wire transfers to “mule accounts”—controlled third-party accounts used to break the audit trail.
  5. The Laundering Cycle: Once the funds reached the mule accounts, they were rapidly converted into stablecoins like USDT and USDC. These digital assets were then moved through a complex web of decentralized wallets before being consolidated and off-ramped through clandestine financial networks, most notably one identified as “Dólar Belgrano.”

Supporting Data: The Scale of the Operation

The scale of Operation Tenevoy was significant, impacting at least 40 companies across Argentina. The financial footprint of the crime was uncovered through forensic analysis of the seized digital assets. Authorities performed 17 coordinated raids in Buenos Aires, leading to the arrest of five individuals and placing seven others under formal investigation.

'Mekotio', el troyano bancario activo en Latinoamérica que con un simple correo de 'importante' engañó a 40 empresas y desató una estafa millonaria

The seizures included:

'Mekotio', el troyano bancario activo en Latinoamérica que con un simple correo de 'importante' engañó a 40 empresas y desató una estafa millonaria
  • Cryptocurrency Assets: Over $150,000 in various stablecoins.
  • Fiat Currency: Approximately $32,000 in cash.
  • Investment Holdings: Over $60,000 in brokerage and investment accounts.
  • Digital Infrastructure: A cache of mobile phones, high-performance laptops, and encrypted hard drives that are currently being decrypted by forensic experts to map the full extent of the syndicate’s reach.

The Role of Mekotio: A Persistent Regional Threat

Mekotio is not a new player in the cybersecurity threat landscape. For years, it has been documented by cybersecurity researchers—most notably by firms like ESET—as a persistent threat in the Southern Cone. Its versatility allows it to pivot from simple credential theft to more advanced tactics, such as replacing the destination address of a cryptocurrency wallet when a user copies it to their clipboard.

'Mekotio', el troyano bancario activo en Latinoamérica que con un simple correo de 'importante' engañó a 40 empresas y desató una estafa millonaria

In recent campaigns, the malware has been observed impersonating tax authorities in Mexico and Chile, as well as public utility companies in Argentina. Its ability to adapt to local cultural and administrative contexts is what makes it particularly lethal. By masquerading as the entities that businesses interact with on a daily basis, Mekotio exploits the "trust gap" in corporate digital communication.

'Mekotio', el troyano bancario activo en Latinoamérica que con un simple correo de 'importante' engañó a 40 empresas y desató una estafa millonaria

Official Responses and Judicial Implications

The judicial response to Operation Tenevoy underscores the growing cooperation between law enforcement agencies and the private sector in tackling cybercrime. Prosecutors have emphasized that the investigation was not just about catching the perpetrators, but about dismantling the “financial bridge” that allowed the stolen money to move from the digital realm to the physical, cash-based economy.

'Mekotio', el troyano bancario activo en Latinoamérica que con un simple correo de 'importante' engañó a 40 empresas y desató una estafa millonaria

Authorities are currently focusing on the connection between the digital malware operators and the "Dólar Belgrano" structure. This suggests a sophisticated division of labor: while the hackers were responsible for the technical breach, they relied on a separate, specialized group to manage the laundering of funds. This structure is a hallmark of modern, professionalized cybercrime, where disparate groups provide "crime-as-a-service" to one another.

'Mekotio', el troyano bancario activo en Latinoamérica que con un simple correo de 'importante' engañó a 40 empresas y desató una estafa millonaria

Strategic Implications: Lessons for the Business World

The success of Operation Tenevoy serves as a wake-up call for corporations regarding their internal security protocols. Cyber-experts argue that technical defenses—such as antivirus software and firewalls—are no longer sufficient.

'Mekotio', el troyano bancario activo en Latinoamérica que con un simple correo de 'importante' engañó a 40 empresas y desató una estafa millonaria

Recommended Defensive Strategies:

  1. Dual-Authorization Protocols: Financial institutions and corporations should implement a "four-eyes" policy for all external transfers. No significant movement of funds should be possible without the digital authorization of two distinct, high-level employees.
  2. Restrictive Access Policies: The use of remote access tools (RATs) should be strictly audited and limited. Many Trojans rely on these tools to gain a foothold; restricting them reduces the "attack surface" available to malware.
  3. Advanced Endpoint Detection (EDR): Companies should transition from static antivirus solutions to EDR systems that monitor for behavioral anomalies, such as an application suddenly attempting to interact with banking credentials or browser memory.
  4. Continuous Training: The "human firewall" remains the weakest link. Regular, simulated phishing training can teach employees to identify the subtle red flags of a sophisticated fraud attempt, such as mismatched email headers or unusual file extensions.
  5. Multi-Factor Authentication (MFA) Evolution: While standard MFA is a baseline, it is no longer foolproof against advanced Trojans like Mekotio. Businesses should look toward hardware-based security keys (like YubiKeys) that are resistant to the interception techniques used by modern banking malware.

Conclusion

Operation Tenevoy is a grim milestone in the history of cybercrime in Latin America. It demonstrates that the convergence of banking Trojans, decentralized finance (DeFi), and organized money laundering has created a formidable adversary for the business community.

'Mekotio', el troyano bancario activo en Latinoamérica que con un simple correo de 'importante' engañó a 40 empresas y desató una estafa millonaria

As the investigation proceeds, the legal outcomes will set a precedent for how these cases are handled in Argentine courts. For businesses, the message is clear: the era of assuming that a "simple email" is harmless is over. In a hyper-connected digital economy, every click, every attachment, and every transaction must be treated with the highest degree of professional skepticism. The cost of failing to do so, as dozens of Argentine companies have learned, is measured in more than just dollars—it is measured in the loss of corporate trust and the disruption of business continuity.

Leave a Reply

Your email address will not be published. Required fields are marked *