New banking trojan “CarnavalHeist” targets Brazil with overlay attacks
ID: 8e74e233-2c51-5609-9859-b3afb854c10a
STIX ID: report--8e74e233-2c51-5609-9859-b3afb854c10a
Feed Name: Cisco Talos
Threat Score
**Cisco Talos analysis of CarnavalHeist:** This report describes an active Brazilian-origin banking trojan campaign (CarnavalHeist) targeting Brazilian users via invoice-themed phishing, using a Python-based loader and Delphi DLLs to inject a banking trojan that performs overlay attacks, keylogging, screen/QR capture, and remote access; the report includes detailed TTPs, DGA and C2 analysis, IOCs, and attribution evidence to specific Brazilian operators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
