Amavaldo is a distinct Latin American banking trojan family associated with the Brazilian banking-malware ecosystem. It has been identified as one of at least 11 separate but closely related families that share code patterns, distribution logic, execution techniques, and operator tradecraft while remaining operationally distinct. Amavaldo primarily targets Windows systems and follows the characteristic regional banking-trojan model of monitoring active windows for targeted financial institutions and using institution-themed fake pop-up workflows to steal sensitive information during live operator-assisted fraud.
The family is strongly linked to the broader cluster that includes Casbaneiro, Grandoreiro, Mekotio, Mispadu, Guildma, Numando, and Vadokrist. Across this ecosystem, Amavaldo shares uncommon string-encryption approaches, similar distribution components, and overlapping execution methods. Amavaldo is specifically noted as using communication protocols based on the Delphi Remote Access PC component and as employing DLL side-loading combined with an injector DLL. Code similarities have also been observed between the Amavaldo injector and other malware, including custom stream-cipher routines and PowerShell-based distribution elements reused by related families.
Like other Latin American banking trojans, Amavaldo has been associated with phishing-led delivery chains that commonly rely on spam campaigns, ZIP archives, MSI installers, scripting languages, and staged payload retrieval. These families frequently establish persistence through Run-key or Startup-folder mechanisms and use obfuscation and custom cryptography to hinder analysis and detection. Shared ecosystem behaviors include screenshot capture, active-window scanning, anti-protection measures against banking-security software, and manual attacker interaction during credential theft.
Amavaldo was active during the main period of expansion of Latin American banking trojans and was among the families observed as part of the region’s coordinated-looking evolution and code-sharing culture. It was later assessed as becoming dormant around November 2020. Despite dormancy, Amavaldo remains significant as a representative family in the Latin American banking-trojan landscape because of its technical overlap with multiple other families and its role in illustrating cooperation among separate financially motivated threat actors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
T1047 Windows Management Instrumentation ✅ ❌ ❌ ✅ ❌ ❌ ✅ ✅ ✅ ❌ ❌ ❌
T1053.005 Scheduled Task/Job: Scheduled Task ✅ ✅ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌ ❌
T1059.001 Command and Scripting Interpreter: PowerShell ✅ ✅ ❌ ❌ ❌ ❌ ✅ ✅ ❌ ✅ ✅ ❌
Operators need to react to this situation and manually command the malware to display the fake pop-up window and take control of the victim’s machine
to steal credentials, they tend to use either fake pop-up windows or keyloggers
periodically scanning active windows based on name or title
T1082 System Information Discovery ✅ ✅ ✅ ✅ ✅ ✅ ✅ ✅ ✅ ✅ ✅ ✅
T1083 File and Directory Discovery ✅ ✅ ✅ ✅ ✅ ✅ ✅ ✅ ✅ ❌ ❌ ❌
Operators need to react to this situation and manually command the malware to display the fake pop-up window and take control of the victim’s machine
to steal credentials, they tend to use either fake pop-up windows or keyloggers
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as another malware/injector with a similar custom stream cipher; not the subject of the report.
Latin American banking trojan family discussed as one of the active families in ESET's series; it mainly targets banking users and was noted as becoming dormant around November 2020.
Referenced as another South American banking trojan expanding operations internationally.
Referenced as a related LATAM banking trojan sharing code similarities with Ousaban.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.