Casbaneiro Banking Trojan Targets Latin American Banks
Key Takeaways Casbaneiro, a sophisticated banking Trojan, is actively targeting online banking users across Latin America, specifically in Argentina, Peru, Colombia, and Mexico. The attack chain...
Key Takeaways
- Casbaneiro, a sophisticated banking Trojan, is actively targeting online banking users across Latin America, specifically in Argentina, Peru, Colombia, and Mexico.
- The attack chain begins with personalized phishing emails containing PDF lures that mimic urgent invoices or legal notices.
- The malware employs advanced evasion techniques, including geographical IP filtering, multi-stage downloads, and obfuscated command-and-control (C2) communications, making detection challenging.
- Once installed, Casbaneiro remains dormant until a victim navigates to a targeted banking website, at which point it activates to steal sensitive data and facilitate fraudulent transactions.
- The operation harvests contact and email details, posing a risk for future spear-phishing campaigns beyond initial financial fraud.
Casbaneiro Banking Trojan Deploys Sophisticated Attack Chain Across Latin America
Cybersecurity researchers have uncovered an active campaign leveraging the Casbaneiro banking Trojan to compromise online banking accounts throughout Latin America. The operation, which targets users in countries including Argentina, Peru, Colombia, and Mexico, employs a multi-stage attack that leverages social engineering and advanced evasion tactics to steal sensitive financial and personal data.
Table Of Content
Initial Compromise and Stealthy Deployment
The attack initiates with highly convincing phishing emails, designed to appear as critical invoices or legal notifications. These emails often incorporate the recipient’s own email address to enhance their perceived legitimacy. Embedded within these deceptive messages are personalized PDF documents, serving as lures to steer unsuspecting users toward a malicious download sequence. This tactic mirrors other weaponized PDF threats, where seemingly innocuous files become the entry point for malware delivery.
Upon clicking a link within the malicious PDF, the victim’s IP address is immediately checked. Individuals located outside the designated target countries are redirected to benign websites like Google or YouTube, effectively preventing security researchers from easily acquiring the malicious payload. Conversely, legitimate targets are served a page that silently downloads a Base64-encoded ZIP archive. This geographical filtering mechanism significantly reduces the campaign’s exposure and complicates analysis efforts.
The ZIP archive contains an HTA (HTML Application) file. Executing this HTA file triggers further script downloads and performs checks for analysis environments and approved operating system languages. If the system passes these preliminary checks, it proceeds to download three separate components: a legitimate AutoIt interpreter, a compiled script, and a compressed malicious component. This staged delivery, reminiscent of known AutoIt loader abuse patterns, helps obscure the malware’s true intent and makes it more difficult for traditional security solutions to identify the combined threat.
The loader then displays a counterfeit Windows service window, a deceptive maneuver to distract the user. Simultaneously, it extracts the final Casbaneiro payload and injects it into either `RegSvcs.exe` or, if unavailable, `mobsync.exe`. To ensure persistence across system reboots, the malware also creates a shortcut in the Startup folder. These stealthy actions mean an infected user may remain unaware that the visible service prompt is a decoy, not a legitimate system process.
Data Theft and Evasion Techniques
Once Casbaneiro is fully operational, it decrypts its configuration parameters and immediately begins harvesting sensitive information. This includes address book entries and detailed sender and recipient information from Outlook, which it transmits unencrypted to its command-and-control (C2) infrastructure. The Trojan constructs a unique identifier for each compromised system using the computer name, user name, and executable name, then hashes this value to track activity and prevent redundant actions.
A critical aspect of Casbaneiro’s design is its patient approach. The Trojan does not immediately activate its primary command channel. Instead, it lies dormant until the victim navigates to one of the pre-configured, targeted banking websites. Upon detecting a visit to a banking portal, Casbaneiro initiates contact with its C2 servers, transmitting system information and awaiting commands. This allows the attackers to execute various malicious actions, including remote keyboard control, clipboard manipulation, file execution, and arbitrary command execution, specifically during an active online banking session. The malware’s ability to overlay fake windows over legitimate banking interfaces further amplifies the risk of real-time fraud.
Fortinet researchers, who first identified this activity in August 2026, detailed how the campaign utilizes a sophisticated C2 communication strategy. Stolen information is sent to a distributed network of servers. Intriguingly, one of these servers is configured to return an HTTP 403 status code upon receiving Base64-encoded victim data. Rather than indicating an error, this 403 response is an intentional part of the protocol; any other HTTP status prompts the malware to retry the transmission. This deliberate use of a seemingly failed response, coupled with sending different data to different servers and employing malformed HTTP requests, severely complicates network traffic analysis and detection by security tools. This behavior, particularly the bank-triggered activation, draws parallels to the Ousaban banking malware, another threat that waits for specific banking site visits before acting, as Fortinet said in a report shared with Cyber Security News (CSN).
The implications extend beyond immediate financial fraud. The stolen contact and email details can be leveraged for subsequent spear-phishing campaigns, broadening the scope of potential victims and perpetuating the attack cycle.
What You Should Do
- Exercise Extreme Caution with Emails: Treat any unexpected emails, especially those purporting to be urgent invoices or legal notices, with suspicion. Verify the sender and the legitimacy of the request through an independent, trusted channel (e.g., a known phone number or official website) before clicking any links or opening attachments.
- Block HTA File Execution: Configure email gateways and endpoint security solutions to block the execution of HTA (HTML Application) files downloaded from external sources, as these are a common vector for initial infection.
- Monitor for Unusual AutoIt Activity: Security teams should actively monitor for any unusual usage of the AutoIt scripting language or its interpreter on enterprise endpoints, as well as the creation of new shortcuts in the Windows Startup folder.
- Analyze Outbound Network Traffic: Implement robust network monitoring to detect suspicious outbound traffic, particularly browser-triggered communications to unknown IP addresses or domains, and analyze HTTP 403 responses for anomalous patterns that might indicate C2 activity.
- Conduct Regular Employee Training: Provide ongoing cybersecurity awareness training to employees, emphasizing the dangers of phishing, the importance of verifying urgent requests, and how to report suspicious emails or system behavior promptly.
- Review Banking Trojan Tactics: Stay informed about the latest tactics, techniques, and procedures (TTPs) employed by banking Trojans and other financial malware to better recognize warning signs.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| PDF SHA-256 | 6bb4372d0d02ec87b76409f69d445a93910964f8db457bafafb97a011da59e73 |
Malicious PDF lure |
| PDF SHA-256 | 40d253480f752805e58c21266e40afe99afc96feea0d355732af5bea459db1dd |
Malicious PDF lure |
| PDF SHA-256 | bf92a287a3d79afb73a3f2d38877ec37c22a9f4a7d6ac2e0385472298f384fc8 |
Malicious PDF lure |
| PDF SHA-256 | 943d63ace373ee50d074daf84d357f8e5e62ff91c829d87f566bee453d715280 |
Malicious PDF lure |
| PDF SHA-256 | 711c0aa8cde078aa349fb329e3e44e4272ea66a5e651ad8a64893c76a725c859 |
Malicious PDF lure |
| PDF SHA-256 | d910e08a11a4f6f764e7495f4602a00b6024ca6e1b70fe30ba3752b881574365 |
Malicious PDF lure |
| PDF SHA-256 | 47d321c1a232e5cdd1e39a06dadbd79114dc1a2f0f8eac289e6b653a5d126f95 |
Malicious PDF lure |
| PDF SHA-256 | d13ad6fc5fda54e65f1214e554a5123126ac7b3ce6db57566ed7bd0e92d03d85 |
Malicious PDF lure |
| PDF SHA-256 | d04f68079ca90c65223a907f23fae5d068904a2145348b953b1d06e2eaf0bf2c |
Malicious PDF lure |
| PDF SHA-256 | 1b4d5c95f4fc037ca3c359cea5ca2da1285bbadab12bcdcb47f3dad8bc6fa8ed |
Malicious PDF lure |
| PDF SHA-256 | 62ef39ec29966d71c8254f68bd5e320cf24a042d76c12dbafdcc0766861827c5 |
Malicious PDF lure |
| PDF SHA-256 | 1f1a89bef73e4866a198a08e750f96348ce2b82816a8353e9a8a574bfde5f491 |
Malicious PDF lure |
| PDF SHA-256 | ea8af591fe2d605c82bb7831d2ebdfb17cb2659880e1a8a7b0a2dd851dc5e7a3 |
Malicious PDF lure |
| PDF SHA-256 | 0b4d962eef2d06abfe08a8cd0b15edd224d4fae0b57d708aebd77d99667616d5 |
Malicious PDF lure |
| PDF SHA-256 | c521b3a189b0089a2558aa4e42bd9fb5558e1b17917e2e183a4bd9cbcb2ed77e |
Malicious PDF lure |
| PDF SHA-256 | 0849a6b87fbef25089ad0be746f84047b080ba81898a8614da43d4ab60ef735a |
Malicious PDF lure |
| Email SHA-256 | debe871710268e7bb770b72c6772f2e0b8bd40a22b2eabf4b6556ea ba2d71057 |
Phishing email artifact |
| Email SHA-256 | eaec8c6950f394ad5dcd271aa86f08cb2b8374203ecc67015af7ca6 057244390 |
Phishing email artifact |
| Email SHA-256 | 995b1156562150c15970aa2d6b27f0b442d758594d820ec09d53d5 e861fac457 |
Phishing email artifact |
| Email SHA-256 | 918dd413cceed3b8aeaa79e45d9d7b2030d73e2affa4339b8f9d04 3d08844f62 |
Phishing email artifact |
| Email SHA-256 | be5a110ee72ebcf1b7d9e155308a8abc606bd446f8aec1a9f33cd06c a0f3c056 |
Phishing email artifact |
| Email SHA-256 | dc62e645589463a61e6ac562d034a9de4ed897714389eb6b87bb0 2f0bd59d565 |
Phishing email artifact |
| HTA SHA-256 | 4302586202234cdf1ca058fd3c62be0050c8155ed113f3f62337d756e6915044 |
HTA downloader |
| HTA SHA-256 | 85767416f8d1e73833ccaa193263d1198857308b3a1185e6f4ebc4164db8584f |
HTA downloader |
| HTA SHA-256 | f1aa14ebfd2da477edba94b34f09f775485688b5958d82fcb072a837e27e246b |
HTA downloader |
| HTA SHA-256 | c477bdfae91e3df9be29e9eeba785467aff294f5250c2eed406765032cb68756 |
HTA downloader |
| HTA SHA-256 | 6e6bd2f7566ffa52d52fa9d5f048bbb9246d3d50110c6b0c248919ad796c6fd4 |
HTA downloader |
| HTA SHA-256 | 4540c3af3b1d8c52256f4580dd4d002fadb8c5ff4e32e6a41fdf508455c5b697 |
HTA downloader |
| HTA SHA-256 | 92a1428e125f33de012c7f52fb0827be3d7e90e38a0e38083181f8c3312adc9c |
HTA downloader |
| HTA SHA-256 | e57409c5e1f8287900c1c3b3e8c099cef537a02949315eb768c88906b0c65add |
HTA downloader |
| HTA SHA-256 | 5a76669ec410d0b3e21112a4a6fd3207976b299ee27c5fc3d42f2673170ab95e |
HTA downloader |
| HTA SHA-256 | 8092b9de455463296898fcaf8c9955d1c00dae6812c03bba019edf9c059ece33 |
HTA downloader |
| HTA SHA-256 | 99fcabf7c996d6ec077ccd745a158a3a395403d6a3df9d8da179f3cd5faf81b1 |
HTA downloader |
| HTA SHA-256 | 875e8d4137e1016b4be869e36e00a9414e89902fd5592a2fb881ebb0e4bd2f8b |
HTA downloader |
| HTA SHA-256 | bd724bbb27f9a71fd44f1c334b003541761071655fa585b64eed3bd78fc28e01 |
HTA downloader |
| HTA SHA-256 | a42daeca71a6bdc79fd66b8b6ee413562abf7f72ef093292c86c1e9e7c2be456 |
HTA downloader |
| HTA SHA-256 | 7e04e86c07213fed7bebccd9953818b102b1b25b78e5f3707e81bad5054cf4e8 |
HTA downloader |
| HTA SHA-256 | 6547736c31dabb5bef2a290b32a72bf63b5c42dd2a33b5a6520159b41c43b093 |
HTA downloader |
| HTA SHA-256 | 51503ce1373c7fa72a1da5c5c4b30f88c8224686669ba4b64196591414fdc64c |
HTA downloader |
| HTA SHA-256 | 5b3c2442831d4844ea6b86942f1a0ba27170018382cbc362343db63717d0ff02 |
HTA downloader |
| HTA SHA-256 | 71dea06c2271a46fc2fd6092e2ba0c2f5a2cf5ca8f955ee3375e3ca66a5dc52b |
HTA downloader |
| Domain | 128[.]200[.]178[.]68[.]host[.]secureserver[.]net |
Campaign infrastructure |
| Domain | 13[.]189[.]202[.]64[.]host[.]secureserver[.]net |
Campaign infrastructure |
| Domain | 116[.]181[.]62[.]50[.]host[.]secureserver[.]net |
Campaign infrastructure |
| Domain | 48[.]178[.]169[.]192[.]host[.]secureserver[.]net |
Campaign infrastructure |
| Domain | 115[.]201[.]178[.]68[.]host[.]secureserver[.]net |
Campaign infrastructure |
| Domain | 181[.]202[.]178[.]68[.]host[.]secureserver[.]net |
Campaign infrastructure |
| Domain | 135[.]201[.]178[.]68[.]host[.]secureserver[.]net |
Campaign infrastructure |
| Domain | 85[.]182[.]62[.]50[.]host[.]secureserver[.]net |
Campaign infrastructure |
| Domain | 162[.]201[.]178[.]68[.]host[.]secureserver[.]net |
Campaign infrastructure |
| Domain | 129[.]202[.]178[.]68[.]host[.]secureserver[.]net |
Campaign infrastructure |
| Domain | 76[.]180[.]62[.]50[.]host[.]secureserver[.]net |
Campaign infrastructure |
| Domain | gexwalltool[.]com |
Campaign infrastructure |
| Domain | x-wolverine[.]servebbs[.]com |
Campaign infrastructure |
| IP address | 72[.]167[.]48[.]63 |
Campaign infrastructure |
| IP address | 209[.]99[.]188[.]28 |
Campaign infrastructure |
| AutoIt script SHA-256 | fc820eeb054c781693eca78fed1c418f12b27da2c7c7e73281eb07b25cc7d910 |
AutoIt loader component |
| AutoIt script SHA-256 | f76d09cbd455ce18765591b9efa3bde0d31358b6321f7a10fc2e04f65d7407ba |
AutoIt loader component |
| Casbaneiro payload SHA-256 | 7de637539159dc17ceedb0aae783930ee68639b6d8036ef8147027c5ebca3fc8 |
Casbaneiro payload |
| Cryptocurrency address | 0xb4c12078448fdef1f8881a55aab5c81fa194095c |
Embedded cryptocurrency address |
| Cryptocurrency address | bc1q7jt45630rw346729vk5cuatvfyvhfv0330u2p6 |
Embedded cryptocurrency address |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.