Augmented Marauder
Augmented Marauder is a Brazilian cybercrime threat actor also tracked as Water Saci. Reported activity links the group to phishing campaigns targeting Spanish-speaking users in organizations across Latin America and Europe to deliver banking malware including Casbaneiro and Horabot. The group uses a multi-pronged delivery model involving email-based phishing, ClickFix techniques, and WhatsApp-based lures. Observed campaigns begin with phishing emails themed as court summons messages and containing password-protected PDF attachments. The PDFs direct victims to malicious links that download ZIP archives, leading to execution of HTA and VBS payloads. These scripts perform environment and anti-analysis checks, including checks for Avast in one reported chain, retrieve additional payloads from remote servers, and can lead to AutoIt-based loaders that extract and run encrypted components. Reported payload chains ultimately deploy Casbaneiro, with Horabot used as a propagation and account-abuse mechanism. Horabot is described as harvesting contacts from Microsoft Outlook and using compromised email accounts to send phishing emails with dynamically generated, password-protected judicial-themed PDF attachments. A related Horabot DLL has been described as a spam and account hijacking tool targeting Yahoo, Live, and Gmail accounts via Outlook. Supporting reporting also states that Water Saci has previously used WhatsApp Web as a distribution vector for banking trojans such as Maverick and Casbaneiro, and that recent campaigns used ClickFix social engineering to trick users into running malicious HTA files. BlueVoyant assessed the operation as maintaining bifurcated infrastructure combining a WhatsApp-centric Maverick chain with ClickFix- and email-based Horabot attack paths.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Where they're from
Attributed origin per open-source reporting.
- BR
Tradecraft
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
2 malware families attributed to this actor across reporting.
Observables
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a multi-pronged phishing campaign targeting Spanish-speaking users in organizations across Latin America and Europe to deliver the banking trojans Casbaneiro and Horabot.
Brazilian cybercrime group conducting multi-pronged phishing campaigns against Spanish-speaking users in Latin America and Europe to deliver banking trojans, using email phishing, WhatsApp-based propagation, ClickFix social engineering, and email hijacking for malware distribution.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.