Researchers reported that the BBTok banking Trojan has been actively targeting users in Brazil and Mexico, impersonating more than 40 banks to steal 2FA tokens, payment card data, and other banking credentials. The malware campaign uses strong geo-fencing and customized delivery chains that adapt lures to a victim’s country and Windows version, helping operators reduce detection while focusing on regional banking customers. Earlier reporting also documented BBTok activity in Mexico, indicating the malware family has remained active across multiple years.
Check Point said the operators rely on layered obfuscation and living-off-the-land binaries to deploy payloads, including infection chains that use LNK files, a renamed cmd.exe, MSBuild, SMB-hosted XML, and downloader DLLs such as Trammy and Gammy. Analysis of older server-side artifacts showed the operation has evolved since at least 2022, with experimentation involving Follina and XLL-based vectors, while server comments and artifacts suggest with high confidence that the threat actors are Brazilian. The campaign was assessed to have targeted hundreds of users and also supports broader remote-control functions beyond credential theft.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Check Point said analysis of multiple ps_gen.ps1 versions dating back to July 2022 showed the operators continuously changed their server-side payload generation and delivery chains. Older artifacts also showed experimentation with Follina and XLL-based infection vectors.
A 360 Total Security blog post reported BBTok activity in Mexico, establishing that the banking Trojan was active by November 2020. Check Point later stated the malware had been active since at least 2020.
Check Point Research disclosed an active BBTok campaign targeting users in Brazil and Mexico with customized ZIP and ISO lures, geo-fencing, and country-specific downloader DLLs. The report described a new BBTok variant impersonating more than 40 banks to steal 2FA codes and payment card data.
2 references tracked. Mallory keeps watching after this page renders.
research.checkpoint.com
Open sourceblog.360totalsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.