Multiple malware campaigns targeted users and organizations in Brazil with Latin American banking trojans including Metamorfo and Mispadu/URSA, using invoice-themed spam, malicious URLs, ZIP archives, MSI installers, and multi-stage loaders to infect Windows systems. Researchers reported delivery chains involving PowerShell, VBScript, AutoIT, and Delphi payloads, as well as abuse of msiexec.exe, AWS-hosted infrastructure, and DLL search-order hijacking through a renamed legitimate VBoxTray.exe binary that side-loaded a malicious mpr.dll file.
The malware was built to steal banking credentials and broader account data through keylogging, fake banking pop-ups and overlays, and credential-harvesting tools such as NirSoft utilities, while some variants also sought CVV and two-factor authentication details. Reporting tied the activity to infrastructure largely observed in Brazil, a spam botnet with more than 700 compromised systems and over 4,000 fraudulently created BOL email accounts, and a later campaign that targeted up to 98 Brazilian organizations across IT, professional services, manufacturing, financial services, and government.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Symantec said it first identified the 2021 Brazilian banking trojan activity after detecting suspicious attempts to download a file named mpr.dll in a customer environment on September 30, 2021. Investigation linked the activity to a broader campaign affecting multiple Brazilian organizations.
Symantec reported a campaign active from late August 2021 through early October 2021 that targeted up to 98 organizations in Brazil across sectors including IT, professional services, manufacturing, financial services, and government. The attack chain used malicious URLs, AWS-hosted infrastructure, MSI installers, and a large DLL payload side-loaded via a renamed VBoxTray.exe.
Symantec cited prior ESET reporting that in 2020, 11 banking trojan gangs were operating in Latin America and appeared to cooperate through shared tactics, tools, and procedures. This earlier reporting informed Symantec's later assessment of related activity.
Cisco Talos identified a botnet tied to the actor behind Metamorfo campaigns, with more than 700 compromised systems and more than 4,000 unique BOL Online email accounts created for spam operations. Talos said the oldest compromise it identified dated to Oct. 23.
Talos observed a Bitly link used in one of the Brazilian banking trojan campaigns that was created on Oct. 21 and later received 699 clicks. The link redirected victims to attacker-controlled infrastructure hosting PowerShell content.
Cisco Talos reported two concurrent malware distribution campaigns targeting customers of Brazilian financial institutions. The campaigns ran between late October and early November and used spam emails, ZIP attachments, shortened links, and multi-stage PowerShell infection chains to deliver banking trojans.
Trend Micro described a spam-driven campaign delivering the URSA/Mispadu banking trojan through overdue-invoice lures, ZIP archives, MSI installers, obfuscated VBScript, and an AutoIT loader. The malware targeted Spanish- and Portuguese-language systems and used fake banking overlays plus NirSoft tools to steal credentials.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
symantec-enterprise-blogs.security.com
Open sourcetrendmicro.com
Open sourceblog.talosintelligence.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.