FORTIGUARD Labs has identified a campaign using the Casbaneiro banking trojan against financial consumers in Argentina, Peru, Colombia and Mexico. The suspected Latin American cybercriminal group distributes phishing emails and malicious PDFs posing as court notices or invoices, sometimes including the recipient’s email address. Links lead to country-specific domains that check the visitor’s location; users outside the targeted countries are redirected to legitimate sites, while others receive an encrypted archive.
The archive contains an HTML Application that downloads scripts and uses Windows Management Instrumentation to check for sandbox environments and approved system languages. The loader then places an AutoIt interpreter, compiled script and compressed payload in a temporary directory, establishing persistence through a shortcut in the Startup folder. A fake “Microsoft Update Superfetch Core Endpoint Service” window distracts the victim while the malware is unpacked and injected into RegSvcs.exe or mobsync.exe.
Casbaneiro collects Microsoft Outlook contacts and sends them to an external server without encryption. Its distributed command-and-control design includes a server that returns HTTP 403, potentially misleading analysts, while operational communication begins when a victim visits a supported banking website. The malware can capture keystrokes, alter clipboard contents and display fraudulent overlays, and uses malformed HTTP requests to hinder traffic analysis.
FortiGuard Labs recommends filtering suspicious PDF links and external legal or invoice messages, restricting outbound AutoIt connections, and monitoring for injection into the named processes, unusual HTTP requests and infection-marker folders in the Public directory.