Attackers in Brazil used malicious Windows Control Panel Application files (.cpl) as downloaders to install banking Trojans, relying heavily on socially engineered email campaigns themed around local payment and tax documents such as Boleto Bancário and Nota Fiscal Eletrônica. The files abused normal Windows handling of .cpl extensions through control.exe, with malicious logic commonly embedded in the CPlApplet routine—especially the CPL_DBLCLK handler—to fetch and launch second-stage malware.
Analysis of more than 1,500 samples found that 82% were classified as Win32/TrojanDownloader.Banload, with Brazil accounting for the vast majority of detections. Many samples were written in Delphi and included string encryption, resource-based key loading, and anti-virtualization checks for Wine, VMware, and Virtual PC. The downloaded payloads were primarily banking Trojans capable of browser injection, keylogging, screenshot or mouse capture, and encrypted theft of banking credentials, showing a sustained malware ecosystem focused on Brazilian financial fraud.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
By the first quarter of 2015, CPL malware had risen to roughly three out of ten submitted executable samples in Latin America. The report presents this as evidence of the technique's sharp growth through early 2015.
In 2014, Brazil accounted for 76% of global Win32/TrojanDownloader.Banload detections, according to the report. This reflected the concentration of CPL-based downloader activity and banking-malware targeting in Brazil.
The report states that malicious CPL-file campaigns grew sharply in Latin America from 2012 through early 2015, becoming a significant malware distribution method. These campaigns primarily used socially engineered emails to deliver CPL downloaders that fetched banking Trojans.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.