Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
Operators need to react to this situation and manually command the malware to display the fake pop-up window and take control of the victim’s machine
to steal credentials, they tend to use either fake pop-up windows or keyloggers
to steal credentials, they tend to use either fake pop-up windows or keyloggers
Finally, we identified a simple infostealer designed to steal the victim’s Outlook address book and a password stealer intended to harvest Outlook and FileZilla credentials.
periodically scanning active windows based on name or title
T1082 System Information Discovery ✅ ✅ ✅ ✅ ✅ ✅ ✅ ✅ ✅ ✅ ✅ ✅
T1083 File and Directory Discovery ✅ ✅ ✅ ✅ ✅ ✅ ✅ ✅ ✅ ❌ ❌ ❌
Operators need to react to this situation and manually command the malware to display the fake pop-up window and take control of the victim’s machine
to steal credentials, they tend to use either fake pop-up windows or keyloggers
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Dormant Latin American banking trojan family active mainly in Mexico, with country-specific builds and related modules including a backdoor, spam tool, Outlook address-book infostealer, and credential stealer for Outlook and FileZilla.
Latin American banking trojan family included among malware families exhibiting overlapping implementation and operational techniques.
Latin American banking trojan that uses the common banking-trojan workflow of system profiling and fake banking pop-up windows. It has used DLL side-loading and shared VBScript obfuscation tooling with Casbaneiro.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.