Catasia is a banking-focused malware campaign/family observed by SCILabs since at least 2015 and active in events documented through January 2019. The activity is focused on victims in Mexico and is broadly distributed across sectors, with the stated objective of redirecting Banco Santander users to phishing pages to steal online banking credentials; victim email credentials are also targeted. Initial access is delivered through phishing emails impersonating major Mexican organizations such as CFE and SAT. These lures direct victims to download nested ZIP archives containing a dated executable, with filenames matching the phishing date; SCILabs noted this nested-ZIP delivery structure as specific to Catasia. Some variants use .cpl or .scr payloads instead of .exe.
The first-stage malware establishes persistence, creates a second instance of a legitimate process such as explorer.exe or msiexec.exe, and injects malicious code into it. In January 2019 samples, it installed under C:\ProgramData\Google Updater 2.03\ and maintained persistence via registry RunOnce/Run values such as HKU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\Google Updater 2.03 and HKU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Google Updater 2.03; earlier events used Device Driver Setup run keys under HKCU. The malware also attempted to prevent copying of its file via Windows API mechanisms.
Catasia uses rotating command-and-control infrastructure, notably moscow*.online domains, iterating through embedded domains if one fails. January 2019 domains included moscow66.online, moscow77.online, moscow88.online, moscow99.online, moscow00.online, and moscow12.online. C2 traffic included HTTP POST requests to /forum/logout.php with a consistent nine-variable body format. The campaign downloaded a second-stage payload referred to as KeyMoscow/KeyRedir, typically named KeyMoscow.xx.yy.exe, which generated periodic requests to /red/info.php to retrieve configuration used for browser redirection. In the January 2019 activity, that configuration redirected browsers to a Banco Santander phishing URL at hxxps://casgp.com/mx/home/eai/EaiEmpresasWAR/inicio.do. Reported second-stage behavior also included clipboard monitoring, cryptocurrency wallet-related strings such as Bitso and LocalBitcoins, and attempts to disable key Windows services.
A third-stage component, hvnc.exe, provides hidden VNC remote access for covert post-compromise actions and interactive fraud. SCILabs assessed the January 2019 events as highly consistent with October-December 2018 activity and with long-running TTPs previously documented for the same operator set. Mentioned infrastructure overlaps indicate some domains have also appeared in telemetry associated with other malware campaigns, but the directly supported attribution in the content is to the same Catasia operator set across these campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware family referenced as using some of the same/shared infrastructure domains observed across multiple LATAM malware campaigns, suggesting possible infrastructure rental/sharing.
Campaña/malware modular observado desde 2015 que se distribuye por phishing (ZIP con ejecutable) y opera por fases: un primer payload establece persistencia e inicia C2 para descargar una segunda fase que redirige navegación bancaria a sitios de phishing y roba credenciales (banca y correo), con capacidades adicionales como monitoreo de portapapeles y búsqueda de billeteras/indicadores de criptomonedas; puede descargar una tercera fase de control remoto (HVNC).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.