CarnavalHeist is a Brazilian banking malware operation associated with the AllaSenha malware lineage and later assessed as a predecessor of NFe-RAT. It is part of a financially motivated cybercrime ecosystem focused on banking fraud in Brazil. The lineage is characterized by multi-stage phishing-driven infection chains, use of Windows-native protocol abuse and staged loaders, embedded Python components, and in-memory delivery of Delphi banking trojans. Later descendant activity linked to this lineage used tax-invoice lures themed around Brazil’s electronic invoicing system, anti-analysis checks, persistence through user-run startup mechanisms, and reflective DLL injection to avoid writing the final payload to disk. The malware family’s core functionality centers on theft of online-banking credentials and fraudulent financial transactions. Capabilities observed in the lineage include bank-specific credential theft overlays targeting numerous Brazilian financial institutions, remote control of infected systems, keylogging, screen capture, and interference with remote-support tools to hinder remediation. The lineage also supports abuse of Brazil’s PIX instant-payment ecosystem, including QR-code capture and transaction facilitation, indicating a strong focus on direct monetization through account takeover and payment fraud. Victimology associated with this lineage is concentrated in Brazil. Observed victims have included organizations and users across multiple Brazilian states, and at least one likely healthcare-sector victim was identified in descendant operations, indicating that opportunistic targeting can affect sectors beyond retail banking customers when financially useful. CarnavalHeist is best understood as a Brazilian cybercriminal banking-trojan cluster rather than a state-sponsored actor, with tradecraft optimized for credential theft, persistence, defense evasion, and post-compromise fraud.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.