The Bizarro banking Trojan, long associated with Brazilian cybercrime, expanded its operations to victims in Spain, Portugal, France, Italy, Germany, Argentina, Chile, and Brazil, broadening a campaign focused on stealing online banking credentials and enabling fraud. Researchers said the malware was delivered through spam emails that pushed victims to download MSI installers, which then retrieved additional payloads from compromised websites, hacked WordPress servers, and cloud-hosted infrastructure on Azure and AWS.
Once installed, Bizarro used heavy obfuscation and a backdoor supporting more than 100 commands to disrupt browser sessions, capture screens, log keystrokes, and hijack clipboard data. The operators also relied heavily on social engineering, displaying fake banking pop-ups, bogus security-update prompts, and requests for two-factor authentication codes, while also using malicious QR codes that could redirect victims to Android malware to extend the fraud chain beyond desktop systems.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
The reference reports that recent Bizarro samples use evolved protection and obfuscation techniques, while detailing the malware's spam-delivered MSI installers, staged payload downloads, banking-session disruption, credential theft, clipboard hijacking, keylogging, and social-engineering features.
Bizarro was observed targeting users in Spain, Portugal, France, Italy, Argentina, Chile, Germany, and Brazil, with attempts to steal credentials from customers of 70 banks across Europe and South America.
The reference identifies Bizarro as a banking Trojan family originating from Brazil before expanding to other regions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.