Attack flow | Image: FortiGuard Labs
At a glance
- Malware family: Casbaneiro
- Threat actor: Unknown Latin American cybercriminal group (suspected attribution)
- Targets or victims: Banking customers across Argentina, Peru, Colombia, and Mexico
- Delivery vector: Phishing emails and malicious PDF attachments
- Key capabilities: Geofencing, clipboard hijacking, fake overlay windows, distributed network communication
- Source: FortiGuard Labs
TL;DR
FortiGuard Labs identified an aggressive wave of the Casbaneiro banking trojan targeting financial consumers across Latin America. The attackers deploy malicious lures using fake legal notices and invoices to deliver multi-stage loaders. System administrators must monitor unusual AutoIt processes and enforce strict email filtering to prevent intrusions.
Delivery
The attack begins when victims receive fraudulent emails or malicious PDF documents. These documents mimic official court notifications or invoice receipts to create false urgency. Furthermore, the operators personalize these files by inserting the victim’s email address directly into the text. Attackers register country-code web domains to focus their attacks on specific regions. Observed victims reside primarily in Argentina, Peru, Colombia, and Mexico.
When a recipient clicks the embedded link, the remote server inspects the visitor’s geographic location. “If the user’s IP address does not originate from the targeted country, the webpage redirects the user to legitimate websites, such as Google or YouTube.” Conversely, visitors from target countries receive an encrypted archive through automated browser downloads. This strict geofencing mechanism prevents foreign security researchers from analyzing the malicious landing infrastructure.
Infection Chain
The downloaded archive contains an HTML Application file that initiates the next phase of the compromise. This component contacts a remote host to fetch script packages containing embedded JScript code. The script runs Windows Management Instrumentation queries to inspect the system environment. It checks whether the endpoint operates within a sandbox analysis machine. Additionally, the script inspects system language settings before proceeding. “The script proceeds with the remaining execution only if the detected OS language matches one of the languages on the predefined whitelist,” reads the report.
Next, the loader downloads three distinct files into a temporary directory on the local drive. These components include an AutoIt interpreter, a compiled script, and a compressed payload archive. Because the AutoIt interpreter represents legitimate software, standalone antivirus scanners often ignore the individual files. The script achieves persistence by placing a shortcut link directly inside the user Startup folder.
When the loader executes, it displays a fraudulent progress window titled “Microsoft Update Superfetch Core Endpoint Service.” This fake interface distracts the victim while the background script unpacks the payload. Finally, the script injects the unpacked payload into legitimate Windows system processes, specifically targeting RegSvcs.exe or mobsync.exe.
Command-and-Control and Data-Exfiltration Behaviour
Once active in memory, the Casbaneiro banking trojan decrypts configuration strings and verifies system parameters. The malware uses an algorithm similar to the Ousaban banking malware to assemble fragmented strings at runtime. It halts execution if it discovers English, French, or German default system language settings.
The malware collects contact information from local Microsoft Outlook stores immediately after setup. It sends these contact lists directly to an external collection server without encryption. Subsequently, the implant contacts a second server using Base64-encoded strings to report initial system identifiers. Curiously, this second server responds with an HTTP 403 Forbidden code. “This behavior may mislead analysts into concluding that the C2 infrastructure is unavailable, potentially leading them to overlook the actual C2 server,” the report explains.
Actual interactive communication begins only after the victim visits a supported financial website. When the user navigates to a target bank, the implant connects to a third server. The operators then issue commands to capture keystrokes, manipulate clipboard contents, and display deceptive overlay windows. In a detailed analysis of Casbaneiro, researchers noted that attackers distribute data across multiple servers to obscure network patterns. Furthermore, the malware transmits malformed HTTP packets with massive content lengths to confuse traffic inspection tools.
Defense or Detection Guidance
Organizations should configure email security gateways to inspect and block inbound messages containing suspicious PDF links. Mail filters should quarantine messages bearing invoices or legal notices from external, unverified senders. Furthermore, network defenders must restrict outbound connections from administrative utilities like AutoIt interpreters.
Security teams should monitor process memory for unauthorized process injection inside RegSvcs.exe and mobsync.exe. Teams can also detect infections by hunting for specific infection marker folders created inside the Public user directory. Finally, security operations centers must inspect network traffic for anomalous HTTP requests lacking standard host headers. Regular employee training on phishing lures significantly reduces initial compromise rates across enterprise environments.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!