ESET detailed the Vadokrist banking trojan as an actively developed malware family focused almost exclusively on Brazil, with tracking dating back to 2018. Written in Delphi, the malware includes backdoor capabilities commonly used in banking fraud, including mouse and keyboard control, keylogging, screenshots, and browser disruption. Researchers said Vadokrist also contains substantial unused code that appears intended to complicate analysis, and it relies on encrypted remote configuration files—often hosted on public storage services—to obtain command-and-control information and downloader instructions.
Recent campaigns distributed Vadokrist through spam emails carrying nested ZIP archives that ultimately delivered MSI and CAB files, followed by JavaScript-based persistence and direct installation of the trojan without a separate downloader in that infection chain. ESET said the malware uses a custom "TripleKey" cryptographic scheme also seen in other Latin American banking trojans, with occasional use of RC4 and historical use of TwoFish, and noted infrastructure and development similarities with Amavaldo, Casbaneiro, Grandoreiro, and Mekotio, indicating shared tradecraft across the regional banking-malware ecosystem.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
ESET published a detailed analysis of Vadokrist covering its Delphi codebase, anti-analysis padding, cryptography, distribution chains, persistence, remote configuration, and similarities with other Latin American banking trojans. The report also described recent MSI-based spam delivery that installs the trojan directly.
ESET reported that it has tracked the Vadokrist Latin American banking trojan since 2018. The malware operates almost exclusively in Brazil.
4 references tracked. Mallory keeps watching after this page renders.
welivesecurity.com
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.