Brazilian banking malware has evolved from basic keyloggers and phishing Trojans into more sophisticated toolsets that use obfuscation, encryption, process injection, browser automation, remote administration, and even ransomware techniques. Researchers said operators adapted quickly to banking defenses such as virtual keyboards, machine fingerprinting, and two-factor authentication by shifting to mouseloggers, hosts-file redirection, Internet Explorer automation, RunPE-style loaders, AutoIt and .NET crypters, and live operator-controlled remote access Trojans, with code quality and operational tradecraft improving markedly over time.
One delivery method highlighted in later activity used malformed ZIP archives prefixed with a UTF-8 Byte Order Mark to evade some email scanners and make the files appear corrupted to certain tools while remaining extractable with common utilities. The recovered loader decrypted an embedded DLL from its resources with an XOR-based routine, executed the exported function BICDAT, then fetched a second-stage password-protected ZIP that delivered a Banking RAT seen broadly in Brazil and Chile, underscoring how Brazilian cybercriminals combined local banking fraud expertise with increasingly advanced malware packaging and execution chains.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
The Securelist article states that McAfee published reporting in 2013 on a malware delivery technique that prepended a UTF-8 Byte Order Mark to ZIP archives. The technique had been used by Russian gangs to distribute malware capable of modifying the Windows hosts file.
Securelist reports a Brazilian spear-phishing campaign that used ZIP archives prefixed with a UTF-8 BOM to evade some scanners and appear corrupted in default Windows handling while remaining extractable by WinRAR and 7-Zip. The extracted loader decrypted an embedded DLL, executed its exported function "BICDAT," downloaded a second password-protected ZIP, and ultimately installed a Banking RAT variant widespread in Brazil and Chile.
Securelist describes Brazilian banking malware as evolving from early Delphi and Visual Basic 6 keyloggers and plaintext-configured phishing Trojans into more sophisticated malware using mouselogging, browser automation, obfuscation, encryption, process hollowing, .NET tooling, and operator-driven RAT capabilities. The evolution was driven in part by banks introducing defenses such as virtual keyboards, machine identification, and two-factor authentication.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.