AllaSenha is a Brazilian banking trojan/RAT in the AllaKore ecosystem, described as a custom variant likely based on KL Gorki code and assessed in later reporting as part of the AllaSenha/CarnavalHeist lineage from which NFe-RAT directly evolved. It is focused on stealing credentials for Brazilian bank accounts, including passwords and 2FA artifacts such as tokens and QR codes, and uses operator-driven overlays and RAT functionality to hijack authentication flows. Reported targets include Brazilian financial institutions such as Banco do Brasil, Itaú Unibanco, Bradesco, Santander, Banco Safra, Sicredi, Sicoob, Unicred, Banrisul, and Caixa Econômica Federal.
Observed delivery used phishing emails impersonating Brazilian electronic invoice notifications (NFS-e / Nota Fiscal), including fake nota fiscal sites reached via is[.]gd short links and domains such as nfe-digital[.]digital, nfe-digital[.]top, nfe-pdf[.]shop, and notas-pdf[.]shop. The infection chain abused the Windows search/search-ms protocol and WebDAV to present a remote share containing a malicious LNK such as NotaFiscal.pdf.lnk or NF410296447634.pdf.lnk. The LNK created a decoy PDF and launched a BAT/PowerShell stage that downloaded the official embedded Python distribution from python.org, renamed pythonw.exe, and executed a base64-encoded Python stager entirely in memory.
The Python stage, referred to as BPyCode/CodePy in reporting, used a DGA to generate daily C2 targets and communicated over raw TCP, sending beacon strings such as "pyCodeV10 - NEWW" or "pyCodeV1 - {hostname}|{os_version}|{cpu_name}". It retrieved serialized loader content and encrypted ZIP payloads, established persistence by writing a stager to disk and creating an HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run registry value, and then loaded a Delphi DLL loader in memory. The loader, identified as ExecutorLoader/executor.dll and exporting Force, copied or renamed mshta.exe, launched it, and reflectively injected the final Delphi payload into that process without writing the PE to disk. Samples were reported as UPX-packed 32-bit Delphi DLLs.
AllaSenha uses Azure-hosted infrastructure for command and control, including daily-rotated hostnames under *.brazilsouth.cloudapp.azure[.]com in 2024 reporting and later Azure Brazil South relay infrastructure in 2026 reporting. C2 uses raw ASCII/TCP with command delimiters formatted as <|COMMAND|>. Reported capabilities include credential theft, capture of PIX-related QR codes for instant-payment fraud, keyboard and mouse control, remote desktop/screen interaction, keylogging, screen capture, and anti-support behavior such as the <|FECHAR-ANYDESK|> command to terminate AnyDesk. The malware and associated loaders also included a Broadwell CPU string check as an anti-analysis measure.
High-confidence indicators mentioned in the content include infrastructure and artifacts such as 191.232.38[.]222:80, 20.195.216.43, 189.37.69.81, the phishing domains above, the password Snh2301Snh2301 used for ZIP archives and reused operationally, the internal DLL name Access_PC_Client_dll.dll, and hashes including ExecutorLoader SHA-256 99d0de52a63e5ff790e468dbb8cd0d5273b51ca3b67b5963c0bdedc3a4f44f12, packed AllaSenha SHA-256 65d86160cd4a08d60ada7fcafb7ed9493bf6dacfa098dba27f7851f1bb8de841, and unpacked AllaSenha SHA-256 ac4b4b6cfe4d4e8710384246c008764cdb7547a6c3081e72687fefdf0614c7a5. Attribution to a specific known threat actor was not established in the cited reporting, though artifacts referenced usernames such as bert1m, xxb3xx, and maria and a Portuguese-language/Brazilian operating context.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
“It starts with a phishing email… The phishing email impersonates a notification for an electronic invoice (‘NFS-e’)… Malicious emails contain a link to the is[.]gd link shortener… which redirects to a phishing website…”
“…LNK… disguised as a PDF file… creates and opens a fake invalid PDF file… ExecutorLoader… copies… mshta.exe binary to another file using a random name…”
“ExecutorLoader… injects the payload into a (renamed) mshta.exe instance… memory is allocated using VirtualAlloc… A thread is then created inside the remote mshta.exe process…”
“The protocol that is used to download from staging servers is raw TCP… C2 communications… use raw ASCII text over a TCP socket.”
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Brazilian banking malware lineage referenced as the predecessor family to NFe-RAT. The report states NFe-RAT structurally matches AllaSenha in internal DLL naming, loader naming, infection chain, payload format, protocol family, compiler lineage, and hosting patterns.
Brazil-focused banking trojan delivered as a 32-bit UPX-packed DLL. It steals banking credentials and supports interactive fraud/ATS-style operator control (e.g., freezing the desktop, presenting fake bank/2FA windows to capture tokens/QR codes). Uses a date-based DGA to rotate Azure-hosted C2 (raw ASCII over TCP) and only beacons when it finds data of interest (banking artifacts/credentials).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.