logo

Bank Trojan 'Casbaneiro' Worms Through Latin America

ID: 6b55ca3e-ec76-57e0-880a-c2d2fb68babb

STIX ID: report--6b55ca3e-ec76-57e0-880a-c2d2fb68babb

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2026-04-02

Date Updated: 2026-04-22

Author: Nate Nelson

...
...

Researchers attribute a regionally spreading banking malware campaign to the Brazilian group Water Saci (Augmented Marauder): attackers deliver password-protected ZIP attachments via judicial-summons-themed phishing, drop the Casbaneiro banking Trojan to capture credentials for banks and crypto platforms, and use a propagation script called Horabot to harvest victims' contacts and auto-send further phishing (also running a parallel WhatsApp campaign). The operation leverages randomized filenames and email-account compromise to bypass email security and increase trust, enabling fast worm-like spread across Latin America and Spain.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.