Threat Advisory

CarnavalHeist Malware Banking Trojan Targeting Users with Fake Invoices

Threat: Malware
Threat Actor Region: Brazil
Targeted Sector: Finance & Banking
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A new banking trojan named "CarnavalHeist" is actively targeting Brazilian users through a malware campaign. This campaign employs financial-themed spam emails with fake invoices to lure victims into downloading the malware. The trojan, also referred to as uses dynamic techniques such as a Python-based loader for DLL injection, keylogging, screen capture, and overlay attacks. The malware contains hardcoded names of prominent Brazilian banks and uses Brazilian Portuguese and slang throughout its code, indicating its specific targeting of Brazilian financial institutions.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A new banking trojan named "CarnavalHeist" is actively targeting Brazilian users through a malware campaign. This campaign employs financial-themed spam emails with fake invoices to lure victims into downloading the malware. The trojan, also referred to as uses dynamic techniques such as a Python-based loader for DLL injection, keylogging, screen capture, and overlay attacks. The malware contains hardcoded names of prominent Brazilian banks and uses Brazilian Portuguese and slang throughout its code, indicating its specific targeting of Brazilian financial institutions.[emaillocker id="1283"]

CarnavalHeist's infection chain begins with unsolicited emails that redirect users to malicious URLs, often using IS.GD URL shortener services. The URLs lead to fake web pages disguised as legitimate invoice download sites, from which a malicious LNK or MSI file is downloaded. The malware uses WebDAV to download these files, which execute further malicious scripts and commands. The final payload is a Delphi-based DLL, dynamically injected into processes to perform credential theft through overlay attacks. The malware communicates with command and control (C2) servers hosted on the BrazilSouth availability zone in Microsoft Azure, using a custom protocol for remote control and data exfiltration.

CarnavalHeist's campaign is assessed to be of Brazilian origin, with the actors behind it identified through operational mistakes during domain registration. WHOIS information revealed their identities, linking them to specific individuals and companies in Brazil. The malware's ongoing development and increasing activity suggest that the threat will continue to evolve. Despite some technical missteps, the malware shows a concerning level of complexity, warranting close monitoring to anticipate and mitigate future iterations of this threat.

THREAT PROFILE:

Tactic Technique Id Technique
Initial Access T1566 Phishing
Execution T1059 Command and Scripting Interpreter
Persistence  T1547 Boot or Logon Autostart Execution
 Defense Evasion T1055 Process Injection
T1027 Obfuscated Files or Information
T1036 Masquerading
Discovery T1010 Application Window Discovery
T1082 System Information Discovery
 Lateral Movement  T1570 Lateral Tool Transfer
Collection T1056 Input Capture
T1113 Screen Capture
T1125 Video Capture
Command and Control T1102 Web Service
T1104 Multi-Stage Channels
T1105 Ingress Tool Transfer
T1571 Non-Standard Port
Exfiltration T1020 Automated Exfiltration
T1041 Exfiltration Over C2 Channel
T1567 Exfiltration Over Web Service

REFERENCES:

The following reports contain further technical details:

https://blog.talosintelligence.com/new-banking-trojan-carnavalheist-targets-brazil/

[/emaillocker]
crossmenu