Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical RCE Flaw in GitHub Enterprise Server Patched, Bounty Awarded
September 14, 2026
Hackers Exploit YouTube Gaming Channels, SEO Poisoning to Deploy RATs
September 14, 2026
Casbaneiro Banking Trojan Targets Latin American Banks
September 14, 2026
Home/Threats/Casbaneiro Banking Trojan Targets Latin American Banks
Threats

Casbaneiro Banking Trojan Targets Latin American Banks

Key Takeaways Casbaneiro, a sophisticated banking Trojan, is actively targeting online banking users across Latin America, specifically in Argentina, Peru, Colombia, and Mexico. The attack chain...

Sarah simpson
Sarah simpson
September 14, 2026 5 Min Read
3 0

Key Takeaways

  • Casbaneiro, a sophisticated banking Trojan, is actively targeting online banking users across Latin America, specifically in Argentina, Peru, Colombia, and Mexico.
  • The attack chain begins with personalized phishing emails containing PDF lures that mimic urgent invoices or legal notices.
  • The malware employs advanced evasion techniques, including geographical IP filtering, multi-stage downloads, and obfuscated command-and-control (C2) communications, making detection challenging.
  • Once installed, Casbaneiro remains dormant until a victim navigates to a targeted banking website, at which point it activates to steal sensitive data and facilitate fraudulent transactions.
  • The operation harvests contact and email details, posing a risk for future spear-phishing campaigns beyond initial financial fraud.

Casbaneiro Banking Trojan Deploys Sophisticated Attack Chain Across Latin America

Cybersecurity researchers have uncovered an active campaign leveraging the Casbaneiro banking Trojan to compromise online banking accounts throughout Latin America. The operation, which targets users in countries including Argentina, Peru, Colombia, and Mexico, employs a multi-stage attack that leverages social engineering and advanced evasion tactics to steal sensitive financial and personal data.

Table Of Content

  • Key Takeaways
  • Casbaneiro Banking Trojan Deploys Sophisticated Attack Chain Across Latin America
  • Initial Compromise and Stealthy Deployment
  • Data Theft and Evasion Techniques
  • What You Should Do
  • Indicators of Compromise (IoCs):-

Initial Compromise and Stealthy Deployment

The attack initiates with highly convincing phishing emails, designed to appear as critical invoices or legal notifications. These emails often incorporate the recipient’s own email address to enhance their perceived legitimacy. Embedded within these deceptive messages are personalized PDF documents, serving as lures to steer unsuspecting users toward a malicious download sequence. This tactic mirrors other weaponized PDF threats, where seemingly innocuous files become the entry point for malware delivery.

Upon clicking a link within the malicious PDF, the victim’s IP address is immediately checked. Individuals located outside the designated target countries are redirected to benign websites like Google or YouTube, effectively preventing security researchers from easily acquiring the malicious payload. Conversely, legitimate targets are served a page that silently downloads a Base64-encoded ZIP archive. This geographical filtering mechanism significantly reduces the campaign’s exposure and complicates analysis efforts.

The ZIP archive contains an HTA (HTML Application) file. Executing this HTA file triggers further script downloads and performs checks for analysis environments and approved operating system languages. If the system passes these preliminary checks, it proceeds to download three separate components: a legitimate AutoIt interpreter, a compiled script, and a compressed malicious component. This staged delivery, reminiscent of known AutoIt loader abuse patterns, helps obscure the malware’s true intent and makes it more difficult for traditional security solutions to identify the combined threat.

The loader then displays a counterfeit Windows service window, a deceptive maneuver to distract the user. Simultaneously, it extracts the final Casbaneiro payload and injects it into either `RegSvcs.exe` or, if unavailable, `mobsync.exe`. To ensure persistence across system reboots, the malware also creates a shortcut in the Startup folder. These stealthy actions mean an infected user may remain unaware that the visible service prompt is a decoy, not a legitimate system process.

Data Theft and Evasion Techniques

Once Casbaneiro is fully operational, it decrypts its configuration parameters and immediately begins harvesting sensitive information. This includes address book entries and detailed sender and recipient information from Outlook, which it transmits unencrypted to its command-and-control (C2) infrastructure. The Trojan constructs a unique identifier for each compromised system using the computer name, user name, and executable name, then hashes this value to track activity and prevent redundant actions.

A critical aspect of Casbaneiro’s design is its patient approach. The Trojan does not immediately activate its primary command channel. Instead, it lies dormant until the victim navigates to one of the pre-configured, targeted banking websites. Upon detecting a visit to a banking portal, Casbaneiro initiates contact with its C2 servers, transmitting system information and awaiting commands. This allows the attackers to execute various malicious actions, including remote keyboard control, clipboard manipulation, file execution, and arbitrary command execution, specifically during an active online banking session. The malware’s ability to overlay fake windows over legitimate banking interfaces further amplifies the risk of real-time fraud.

Fortinet researchers, who first identified this activity in August 2026, detailed how the campaign utilizes a sophisticated C2 communication strategy. Stolen information is sent to a distributed network of servers. Intriguingly, one of these servers is configured to return an HTTP 403 status code upon receiving Base64-encoded victim data. Rather than indicating an error, this 403 response is an intentional part of the protocol; any other HTTP status prompts the malware to retry the transmission. This deliberate use of a seemingly failed response, coupled with sending different data to different servers and employing malformed HTTP requests, severely complicates network traffic analysis and detection by security tools. This behavior, particularly the bank-triggered activation, draws parallels to the Ousaban banking malware, another threat that waits for specific banking site visits before acting, as Fortinet said in a report shared with Cyber Security News (CSN).

The implications extend beyond immediate financial fraud. The stolen contact and email details can be leveraged for subsequent spear-phishing campaigns, broadening the scope of potential victims and perpetuating the attack cycle.

What You Should Do

  • Exercise Extreme Caution with Emails: Treat any unexpected emails, especially those purporting to be urgent invoices or legal notices, with suspicion. Verify the sender and the legitimacy of the request through an independent, trusted channel (e.g., a known phone number or official website) before clicking any links or opening attachments.
  • Block HTA File Execution: Configure email gateways and endpoint security solutions to block the execution of HTA (HTML Application) files downloaded from external sources, as these are a common vector for initial infection.
  • Monitor for Unusual AutoIt Activity: Security teams should actively monitor for any unusual usage of the AutoIt scripting language or its interpreter on enterprise endpoints, as well as the creation of new shortcuts in the Windows Startup folder.
  • Analyze Outbound Network Traffic: Implement robust network monitoring to detect suspicious outbound traffic, particularly browser-triggered communications to unknown IP addresses or domains, and analyze HTTP 403 responses for anomalous patterns that might indicate C2 activity.
  • Conduct Regular Employee Training: Provide ongoing cybersecurity awareness training to employees, emphasizing the dangers of phishing, the importance of verifying urgent requests, and how to report suspicious emails or system behavior promptly.
  • Review Banking Trojan Tactics: Stay informed about the latest tactics, techniques, and procedures (TTPs) employed by banking Trojans and other financial malware to better recognize warning signs.

Indicators of Compromise (IoCs):-

Type Indicator Description
PDF SHA-256 6bb4372d0d02ec87b76409f69d445a93910964f8db457bafafb97a011da59e73 Malicious PDF lure
PDF SHA-256 40d253480f752805e58c21266e40afe99afc96feea0d355732af5bea459db1dd Malicious PDF lure
PDF SHA-256 bf92a287a3d79afb73a3f2d38877ec37c22a9f4a7d6ac2e0385472298f384fc8 Malicious PDF lure
PDF SHA-256 943d63ace373ee50d074daf84d357f8e5e62ff91c829d87f566bee453d715280 Malicious PDF lure
PDF SHA-256 711c0aa8cde078aa349fb329e3e44e4272ea66a5e651ad8a64893c76a725c859 Malicious PDF lure
PDF SHA-256 d910e08a11a4f6f764e7495f4602a00b6024ca6e1b70fe30ba3752b881574365 Malicious PDF lure
PDF SHA-256 47d321c1a232e5cdd1e39a06dadbd79114dc1a2f0f8eac289e6b653a5d126f95 Malicious PDF lure
PDF SHA-256 d13ad6fc5fda54e65f1214e554a5123126ac7b3ce6db57566ed7bd0e92d03d85 Malicious PDF lure
PDF SHA-256 d04f68079ca90c65223a907f23fae5d068904a2145348b953b1d06e2eaf0bf2c Malicious PDF lure
PDF SHA-256 1b4d5c95f4fc037ca3c359cea5ca2da1285bbadab12bcdcb47f3dad8bc6fa8ed Malicious PDF lure
PDF SHA-256 62ef39ec29966d71c8254f68bd5e320cf24a042d76c12dbafdcc0766861827c5 Malicious PDF lure
PDF SHA-256 1f1a89bef73e4866a198a08e750f96348ce2b82816a8353e9a8a574bfde5f491 Malicious PDF lure
PDF SHA-256 ea8af591fe2d605c82bb7831d2ebdfb17cb2659880e1a8a7b0a2dd851dc5e7a3 Malicious PDF lure
PDF SHA-256 0b4d962eef2d06abfe08a8cd0b15edd224d4fae0b57d708aebd77d99667616d5 Malicious PDF lure
PDF SHA-256 c521b3a189b0089a2558aa4e42bd9fb5558e1b17917e2e183a4bd9cbcb2ed77e Malicious PDF lure
PDF SHA-256 0849a6b87fbef25089ad0be746f84047b080ba81898a8614da43d4ab60ef735a Malicious PDF lure
Email SHA-256 debe871710268e7bb770b72c6772f2e0b8bd40a22b2eabf4b6556ea ba2d71057 Phishing email artifact
Email SHA-256 eaec8c6950f394ad5dcd271aa86f08cb2b8374203ecc67015af7ca6 057244390 Phishing email artifact
Email SHA-256 995b1156562150c15970aa2d6b27f0b442d758594d820ec09d53d5 e861fac457 Phishing email artifact
Email SHA-256 918dd413cceed3b8aeaa79e45d9d7b2030d73e2affa4339b8f9d04 3d08844f62 Phishing email artifact
Email SHA-256 be5a110ee72ebcf1b7d9e155308a8abc606bd446f8aec1a9f33cd06c a0f3c056 Phishing email artifact
Email SHA-256 dc62e645589463a61e6ac562d034a9de4ed897714389eb6b87bb0 2f0bd59d565 Phishing email artifact
HTA SHA-256 4302586202234cdf1ca058fd3c62be0050c8155ed113f3f62337d756e6915044 HTA downloader
HTA SHA-256 85767416f8d1e73833ccaa193263d1198857308b3a1185e6f4ebc4164db8584f HTA downloader
HTA SHA-256 f1aa14ebfd2da477edba94b34f09f775485688b5958d82fcb072a837e27e246b HTA downloader
HTA SHA-256 c477bdfae91e3df9be29e9eeba785467aff294f5250c2eed406765032cb68756 HTA downloader
HTA SHA-256 6e6bd2f7566ffa52d52fa9d5f048bbb9246d3d50110c6b0c248919ad796c6fd4 HTA downloader
HTA SHA-256 4540c3af3b1d8c52256f4580dd4d002fadb8c5ff4e32e6a41fdf508455c5b697 HTA downloader
HTA SHA-256 92a1428e125f33de012c7f52fb0827be3d7e90e38a0e38083181f8c3312adc9c HTA downloader
HTA SHA-256 e57409c5e1f8287900c1c3b3e8c099cef537a02949315eb768c88906b0c65add HTA downloader
HTA SHA-256 5a76669ec410d0b3e21112a4a6fd3207976b299ee27c5fc3d42f2673170ab95e HTA downloader
HTA SHA-256 8092b9de455463296898fcaf8c9955d1c00dae6812c03bba019edf9c059ece33 HTA downloader
HTA SHA-256 99fcabf7c996d6ec077ccd745a158a3a395403d6a3df9d8da179f3cd5faf81b1 HTA downloader
HTA SHA-256 875e8d4137e1016b4be869e36e00a9414e89902fd5592a2fb881ebb0e4bd2f8b HTA downloader
HTA SHA-256 bd724bbb27f9a71fd44f1c334b003541761071655fa585b64eed3bd78fc28e01 HTA downloader
HTA SHA-256 a42daeca71a6bdc79fd66b8b6ee413562abf7f72ef093292c86c1e9e7c2be456 HTA downloader
HTA SHA-256 7e04e86c07213fed7bebccd9953818b102b1b25b78e5f3707e81bad5054cf4e8 HTA downloader
HTA SHA-256 6547736c31dabb5bef2a290b32a72bf63b5c42dd2a33b5a6520159b41c43b093 HTA downloader
HTA SHA-256 51503ce1373c7fa72a1da5c5c4b30f88c8224686669ba4b64196591414fdc64c HTA downloader
HTA SHA-256 5b3c2442831d4844ea6b86942f1a0ba27170018382cbc362343db63717d0ff02 HTA downloader
HTA SHA-256 71dea06c2271a46fc2fd6092e2ba0c2f5a2cf5ca8f955ee3375e3ca66a5dc52b HTA downloader
Domain 128[.]200[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure
Domain 13[.]189[.]202[.]64[.]host[.]secureserver[.]net Campaign infrastructure
Domain 116[.]181[.]62[.]50[.]host[.]secureserver[.]net Campaign infrastructure
Domain 48[.]178[.]169[.]192[.]host[.]secureserver[.]net Campaign infrastructure
Domain 115[.]201[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure
Domain 181[.]202[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure
Domain 135[.]201[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure
Domain 85[.]182[.]62[.]50[.]host[.]secureserver[.]net Campaign infrastructure
Domain 162[.]201[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure
Domain 129[.]202[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure
Domain 76[.]180[.]62[.]50[.]host[.]secureserver[.]net Campaign infrastructure
Domain gexwalltool[.]com Campaign infrastructure
Domain x-wolverine[.]servebbs[.]com Campaign infrastructure
IP address 72[.]167[.]48[.]63 Campaign infrastructure
IP address 209[.]99[.]188[.]28 Campaign infrastructure
AutoIt script SHA-256 fc820eeb054c781693eca78fed1c418f12b27da2c7c7e73281eb07b25cc7d910 AutoIt loader component
AutoIt script SHA-256 f76d09cbd455ce18765591b9efa3bde0d31358b6321f7a10fc2e04f65d7407ba AutoIt loader component
Casbaneiro payload SHA-256 7de637539159dc17ceedb0aae783930ee68639b6d8036ef8147027c5ebca3fc8 Casbaneiro payload
Cryptocurrency address 0xb4c12078448fdef1f8881a55aab5c81fa194095c Embedded cryptocurrency address
Cryptocurrency address bc1q7jt45630rw346729vk5cuatvfyvhfv0330u2p6 Embedded cryptocurrency address

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackHackerMalwarephishingSecurityThreat

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

AsyncRAT Injected Via AutoIt Into Microsoft Windows Processes

Next Post

Hackers Exploit YouTube Gaming Channels, SEO Poisoning to Deploy RATs

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical FortiOS, PAN-OS, and Microsoft Flaws Patched
September 14, 2026
Critical Dell ObjectScale flaw allows full system compromise
September 13, 2026
Revolut Data Breach Exposes Customer Passports and Transaction Histories
September 13, 2026
Top Authors
David kimber
David kimber
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us