logo

New Banking Trojan CHAVECLOAK Targets Brazilian Users via Phishing Tactics

ID: fd940425-1706-5a5c-874b-b57c8fc4e2c5

STIX ID: report--fd940425-1706-5a5c-874b-b57c8fc4e2c5

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-03-11

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Fortinet and other vendors have observed active banking malware campaigns: CHAVECLOAK (Windows banking trojan distributed via PDF phishing that downloads a ZIP and uses DLL side‑loading to run a DLL that monitors Brazilian users and steals banking credentials) and mobile campaigns (Copybara and TeaBot) using smishing/vishing, fake overlays, accessibility abuse, and C2 panels to perform on-device fraud and credential exfiltration across multiple European countries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.