EXECUTIVE SUMMARY
A new banking trojan named "CarnavalHeist" is actively targeting Brazilian users through a malware campaign. This campaign employs financial-themed spam emails with fake invoices to lure victims into downloading the malware. The trojan, also referred to as uses dynamic techniques such as a Python-based loader for DLL injection, keylogging, screen capture, and overlay attacks. The malware contains hardcoded names of prominent Brazilian banks and uses Brazilian Portuguese and slang throughout its code, indicating its specific targeting of Brazilian financial institutions.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
A new banking trojan named "CarnavalHeist" is actively targeting Brazilian users through a malware campaign. This campaign employs financial-themed spam emails with fake invoices to lure victims into downloading the malware. The trojan, also referred to as uses dynamic techniques such as a Python-based loader for DLL injection, keylogging, screen capture, and overlay attacks. The malware contains hardcoded names of prominent Brazilian banks and uses Brazilian Portuguese and slang throughout its code, indicating its specific targeting of Brazilian financial institutions.[emaillocker id="1283"]
CarnavalHeist's infection chain begins with unsolicited emails that redirect users to malicious URLs, often using IS.GD URL shortener services. The URLs lead to fake web pages disguised as legitimate invoice download sites, from which a malicious LNK or MSI file is downloaded. The malware uses WebDAV to download these files, which execute further malicious scripts and commands. The final payload is a Delphi-based DLL, dynamically injected into processes to perform credential theft through overlay attacks. The malware communicates with command and control (C2) servers hosted on the BrazilSouth availability zone in Microsoft Azure, using a custom protocol for remote control and data exfiltration.
CarnavalHeist's campaign is assessed to be of Brazilian origin, with the actors behind it identified through operational mistakes during domain registration. WHOIS information revealed their identities, linking them to specific individuals and companies in Brazil. The malware's ongoing development and increasing activity suggest that the threat will continue to evolve. Despite some technical missteps, the malware shows a concerning level of complexity, warranting close monitoring to anticipate and mitigate future iterations of this threat.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Initial Access | T1566 | Phishing |
| Execution | T1059 | Command and Scripting Interpreter |
| Persistence | T1547 | Boot or Logon Autostart Execution |
| Defense Evasion | T1055 | Process Injection |
| T1027 | Obfuscated Files or Information | |
| T1036 | Masquerading | |
| Discovery | T1010 | Application Window Discovery |
| T1082 | System Information Discovery | |
| Lateral Movement | T1570 | Lateral Tool Transfer |
| Collection | T1056 | Input Capture |
| T1113 | Screen Capture | |
| T1125 | Video Capture | |
| Command and Control | T1102 | Web Service |
| T1104 | Multi-Stage Channels | |
| T1105 | Ingress Tool Transfer | |
| T1571 | Non-Standard Port | |
| Exfiltration | T1020 | Automated Exfiltration |
| T1041 | Exfiltration Over C2 Channel | |
| T1567 | Exfiltration Over Web Service |
REFERENCES:
The following reports contain further technical details:
https://blog.talosintelligence.com/new-banking-trojan-carnavalheist-targets-brazil/
[/emaillocker]