The Casbaneiro attack campaign targets users in Latin America using phishing emails and PDF files themed around fake invoices and legal notices as the initial stage. The threat actor uses clipboard injection and fake windows to facilitate fraudulent activities, which are common characteristics of malware families targeting financial institutions and users in Latin America. However, the recent attack revealed distinctive network behaviors that differentiate this campaign from previously observed Casbaneiro behavior. The malware is delivered via a multi-stage infection chain that includes an HTA downloader and an AutoIt loader.
The HTA downloader references an external JavaScript resource that retrieves an externally hosted XML-based script package containing embedded JScript. The JScript performs environment checks through Windows Management Instrumentation (WMI), including sandbox detection and OS language identification, before proceeding with the remaining execution tasks. The malware downloads separate components to a directory and creates persistence by creating an a malicious shortcut file in the Startup folder that executes the AutoIt script.[/subscribe_to_unlock_form]
The Casbaneiro attack campaign targets users in Latin America using phishing emails and PDF files themed around fake invoices and legal notices as the initial stage. The threat actor uses clipboard injection and fake windows to facilitate fraudulent activities, which are common characteristics of malware families targeting financial institutions and users in Latin America. However, the recent attack revealed distinctive network behaviors that differentiate this campaign from previously observed Casbaneiro behavior. The malware is delivered via a multi-stage infection chain that includes an HTA downloader and an AutoIt loader.
The HTA downloader references an external JavaScript resource that retrieves an externally hosted XML-based script package containing embedded JScript. The JScript performs environment checks through Windows Management Instrumentation (WMI), including sandbox detection and OS language identification, before proceeding with the remaining execution tasks. The malware downloads separate components to a directory and creates persistence by creating an a malicious shortcut file in the Startup folder that executes the AutoIt script.[emaillocker id="1283"]
The Casbaneiro campaign exhibits high severity and affects Microsoft Windows platforms. It can be used for future attacks, allowing threat actors to target financial institutions and users in Latin America. The malware injects clipboard data and uses fake windows to facilitate fraudulent activities, making it a significant risk. Defenders must be vigilant and monitor for suspicious activity to prevent reinfection or repeated execution.
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Initial access | T1566.002 | Phishing | Spearphishing Link |
| Execution | T1059.001 | Command and Scripting Interpreter | PowerShell |
| Execution | T1204.002 | User Execution | Malicious File |
| Persistence | T1547.001 | Boot or Logon Autostart Execution | Registry Run Keys / Startup Folder |
| Defence Evasion | T1027.002 | Obfuscated Files or Information | Software Packing |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | - |
The following reports contain further technical details:
[/emaillocker]