Casbaneiro Phishing Targets Latin America and Europe Using Dynamic PDF Lures
ID: d0751f61-2078-50cc-af60-aa5a1d46b3a7
STIX ID: report--d0751f61-2078-50cc-af60-aa5a1d46b3a7
Feed Name: The Hacker News
BlueVoyant researchers detail an active campaign by a Brazil-based cybercrime group (Augmented Marauder / Water Saci) targeting Spanish-speaking users in Latin America and organizations in Europe to deploy the Casbaneiro (Metamorfo) banking trojan. The attack chain begins with court-summons-themed phishing e-mails containing password-protected PDFs that lead to ZIP archives and execution of HTA/VBS/AutoIt loaders which deploy encrypted DLL payloads (staticdata.dll for Casbaneiro and at.dll for Horabot). Horabot is used to hijack accounts and send forged, dynamically generated password-protected PDFs via the victim's Outlook account, while WhatsApp automation and ClickFix social engineering are used for lateral propagation and additional delivery.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
