Water Saci, also tracked as Augmented Marauder, is a Brazilian cybercrime threat actor associated with banking-trojan campaigns targeting Spanish-speaking users and organizations across Latin America and Europe. The group has been linked to delivery and propagation of Casbaneiro, also known as Metamorfo, and Horabot through multi-stage phishing operations that combine email lures, ClickFix-style social engineering, and WhatsApp-based distribution. The actor’s campaigns commonly begin with phishing emails themed as judicial or court summons messages. These lures use password-protected documents and follow-on downloads that lead victims through staged execution chains involving ZIP archives, HTA and VBS scripts, and AutoIt-based loaders. The malware performs environment checking and anti-analysis steps before retrieving and launching additional payloads. Casbaneiro serves as the primary banking trojan payload, while Horabot is used to expand infections by harvesting contacts from Microsoft Outlook, abusing compromised email accounts, and sending tailored phishing messages with dynamically generated attachments to victim contacts. Activity attributed to this actor has also included use of WhatsApp Web as a distribution vector for banking trojans such as Maverick and Casbaneiro. The group demonstrates mature social-engineering tradecraft and post-compromise abuse of victim communications channels to increase reach and evade defenses. Its observed capabilities include phishing-based initial access, credential and account abuse associated with email propagation, anti-analysis and defense-evasion behavior, payload staging and execution through scripts and loaders, and malware-enabled exfiltration of contact data for further targeting. The actor is financially motivated and operates as part of the Brazilian e-crime ecosystem focused on banking fraud and related credential theft.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a multi-pronged phishing campaign targeting Spanish-speaking users in organizations across Latin America and Europe to deliver the banking trojans Casbaneiro and Horabot.
Brazilian cybercrime group conducting multi-pronged phishing campaigns against Spanish-speaking users in Latin America and Europe to deliver banking trojans, using email phishing, WhatsApp-based propagation, ClickFix social engineering, and email hijacking for malware distribution.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.