Bank Trojan 'Casbaneiro' Worms Through Latin America
ID: 6b55ca3e-ec76-57e0-880a-c2d2fb68babb
STIX ID: report--6b55ca3e-ec76-57e0-880a-c2d2fb68babb
Feed Name: Dark Reading
Researchers attribute a regionally spreading banking malware campaign to the Brazilian group Water Saci (Augmented Marauder): attackers deliver password-protected ZIP attachments via judicial-summons-themed phishing, drop the Casbaneiro banking Trojan to capture credentials for banks and crypto platforms, and use a propagation script called Horabot to harvest victims' contacts and auto-send further phishing (also running a parallel WhatsApp campaign). The operation leverages randomized filenames and email-account compromise to bypass email security and increase trust, enabling fast worm-like spread across Latin America and Spain.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
