A high-severity Casbaneiro banking-trojan campaign is targeting Microsoft Windows users in Latin America through phishing emails masquerading as invoices and legal notices. The messages deliver a multi-stage infection chain involving an HTA downloader, an AutoIt interpreter and loader, and a final payload injected into legitimate Windows processes such as RegSvcs.exe or mobsync.exe; persistence is established through a Startup-folder LNK file.
The malware activates command-and-control activity after victims visit targeted banking sites and enables financial fraud through clipboard manipulation and fraudulent windows. It also harvests Outlook address-book data and email metadata, sending it unencrypted to multiple attacker-controlled data-receiving servers. Casbaneiro evades analysis through fragmented runtime string decryption and HTTP 403 responses, while avoiding systems configured in German, French, or English; defenders should prioritize blocking the campaign's published malicious domains, IP addresses, and file hashes and investigate suspicious HTA, AutoIt, and Startup-folder activity.

Get the infrastructure and lures behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Researchers disclosed Casbaneiro's bank-activation behavior, Outlook/address-book collection, process injection, Startup-folder persistence, and its use of HTTP 403 responses as an expected C2 workflow. The disclosure also identified payload and AutoIt-component hashes and campaign infrastructure including gexwalltool[.]com, x-wolverine[.]servebbs[.]com, 72[.]167[.]48[.]63, and 209[.]99[.]188[.]28.
FortiGuard Labs observed a high-severity Casbaneiro banking-trojan campaign targeting Microsoft Windows users in Latin America. The campaign used phishing emails with fake invoice and legal-notice PDF lures to deliver an HTA downloader, AutoIt loader, and injected payload.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 60 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecryptika.com
Open sourcecommunity.gurucul.com
Open sourcefeeds.fortinet.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.