Vadokrist is a Latin American banking trojan active since at least 2018 and operating almost exclusively in Brazil. It is written in Delphi and is part of the closely connected LATAM banking trojan ecosystem that includes families such as Casbaneiro, Grandoreiro, Mekotio, and Amavaldo. Vadokrist shares code, distribution components, and operational patterns with several of these families, including shared downloaders, overlapping infection chains, and common cryptographic and obfuscation approaches.
The malware is designed for interactive online-banking fraud on Windows systems. Its capabilities include simulating mouse and keyboard input, logging keystrokes, taking screenshots, restarting the machine, and interfering with browser activity. It can terminate browser processes when victims attempt to access certain websites, a behavior assessed as helping operators retain control over compromised banking sessions and hinder victim response. Like other regional banking trojans, Vadokrist uses remote configuration to obtain command-and-control information and operational parameters.
Vadokrist commonly protects strings, payloads, and configuration data with custom encryption, especially the TripleKey algorithm, and some versions also use RC4, while older samples used TwoFish. Its binaries contain substantial unused code, likely intended to complicate analysis and evade detection. Persistence is typically established through a Windows Run key or a shortcut placed in the Startup folder.
Observed delivery has centered on spam-driven campaigns using nested ZIP archives that ultimately deliver MSI-based installers and CAB content. In one documented chain, an MSI installer extracts a loader and runs embedded JavaScript that establishes persistence and reboots the system; on startup, the loader executes an embedded DLL containing the banking trojan. Vadokrist has also been observed using DLL side-loading, including with an injector shared with Amavaldo, and it has shared entire distribution chains with Mekotio as well as a Delphi downloader with Grandoreiro. Remote configuration has often been hosted on public storage services.
Vadokrist is one of the distinct but highly interrelated banking trojan families that dominate the Brazilian threat landscape. Its behavior, tooling overlap, and shared tradecraft with other LATAM banking malware indicate sustained development and close cooperation among multiple threat actors rather than an isolated malware lineage.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
T1059 Command and Scripting Interpreter ❌ ✅ ❌ ❌ ✅ ❌ ✅ ❌ ❌ ❌ ✅ ❌
T1059.001 Command and Scripting Interpreter: PowerShell ✅ ✅ ❌ ❌ ❌ ❌ ✅ ✅ ❌ ✅ ✅ ❌
T1059.003 Command and Scripting Interpreter: Windows Command Shell ❌ ✅ ✅ ❌ ✅ ❌ ✅ ✅ ❌ ✅ ✅ ❌
It then executes an embedded JavaScript file that adds a Run key entry, making sure the MSI loader is executed on system startup.
Operators need to react to this situation and manually command the malware to display the fake pop-up window and take control of the victim’s machine
periodically scanning active windows based on name or title
The only thing that is sent to the notification URL is whether an application Core.exe is running – a check familiar from other Latin American banking trojans that try to detect the presence of anti-fraud software Warsaw GAS Tecnologia.
Operators need to react to this situation and manually command the malware to display the fake pop-up window and take control of the victim’s machine
Its backdoor capabilities are typical for this type of threat, being able to manipulate the mouse and simulate keyboard input, log keystrokes, take screenshots, and restart the machine.
T1132.001 Data Encoding: Standard Encoding ❌ ✅ ✅ ✅ ✅ ❌ ❌ ❌ ❌ ❌ ✅ ✅
custom encryption algorithms are favored over established ones
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as another Latin American banking trojan family that previously shared downloaders with Grandoreiro.
Latin American banking trojan family included among the active families tracked by ESET in this series.
Referenced as a related LATAM banking trojan with similar JavaScript distribution components.
Latin American banking trojan referenced as another regional family with similar fake banking window tradecraft and implementation blueprint.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.