Threat Advisory

Casbaneiro Malware Injects Clipboard and Uses Fake Windows for Fraudulent Activities

Threat: Phishing Campaign
Targeted Region: Latin America, Argentina, Peru, Colombia, Mexico
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

The Casbaneiro attack campaign targets users in Latin America using phishing emails and PDF files themed around fake invoices and legal notices as the initial stage. The threat actor uses clipboard injection and fake windows to facilitate fraudulent activities, which are common characteristics of malware families targeting financial institutions and users in Latin America. However, the recent attack revealed distinctive network behaviors that differentiate this campaign from previously observed Casbaneiro behavior. The malware is delivered via a multi-stage infection chain that includes an HTA downloader and an AutoIt loader.

The HTA downloader references an external JavaScript resource that retrieves an externally hosted XML-based script package containing embedded JScript. The JScript performs environment checks through Windows Management Instrumentation (WMI), including sandbox detection and OS language identification, before proceeding with the remaining execution tasks. The malware downloads separate components to a directory and creates persistence by creating an a malicious shortcut file in the Startup folder that executes the AutoIt script.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

The Casbaneiro attack campaign targets users in Latin America using phishing emails and PDF files themed around fake invoices and legal notices as the initial stage. The threat actor uses clipboard injection and fake windows to facilitate fraudulent activities, which are common characteristics of malware families targeting financial institutions and users in Latin America. However, the recent attack revealed distinctive network behaviors that differentiate this campaign from previously observed Casbaneiro behavior. The malware is delivered via a multi-stage infection chain that includes an HTA downloader and an AutoIt loader.

The HTA downloader references an external JavaScript resource that retrieves an externally hosted XML-based script package containing embedded JScript. The JScript performs environment checks through Windows Management Instrumentation (WMI), including sandbox detection and OS language identification, before proceeding with the remaining execution tasks. The malware downloads separate components to a directory and creates persistence by creating an a malicious shortcut file in the Startup folder that executes the AutoIt script.[emaillocker id="1283"]

The Casbaneiro campaign exhibits high severity and affects Microsoft Windows platforms. It can be used for future attacks, allowing threat actors to target financial institutions and users in Latin America. The malware injects clipboard data and uses fake windows to facilitate fraudulent activities, making it a significant risk. Defenders must be vigilant and monitor for suspicious activity to prevent reinfection or repeated execution.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1566.002 Phishing Spearphishing Link
Execution T1059.001 Command and Scripting Interpreter PowerShell
Execution T1204.002 User Execution Malicious File
Persistence T1547.001 Boot or Logon Autostart Execution Registry Run Keys / Startup Folder
Defence Evasion T1027.002 Obfuscated Files or Information Software Packing
Command and control T1071.001 Application Layer Protocol Web Protocols
Exfiltration T1041 Exfiltration Over C2 Channel -

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu