Threat Advisory

Operation Magalenha targets credentials of 30 Portuguese banks

Threat: Malware
Threat Actor Type: Cybercriminal
Targeted Region: Portugal
Threat Actor Region: Brazil
Targeted Sector: Finance & Banking
Criticality: High
[subscribe_to_unlock_form]

Summary:

 An offensive campaign called "Operation Magalenha," a Brazilian hacker organization has been focusing on 30 Portuguese public and private financial institutions since 2021. Targeted companies include, among others, ActivoBank, Caixa Geral de Depósitos, CaixaBank, Citibanamex, Santander, Millennium BCP, ING, Banco BPI, and Novobanco. An analysis of the tools utilized by the threat actor, the different attack channels, and their malware distribution techniques uncovered this campaign.[/subscribe_to_unlock_form]

Summary:

 An offensive campaign called "Operation Magalenha," a Brazilian hacker organization has been focusing on 30 Portuguese public and private financial institutions since 2021. Targeted companies include, among others, ActivoBank, Caixa Geral de Depósitos, CaixaBank, Citibanamex, Santander, Millennium BCP, ING, Banco BPI, and Novobanco. An analysis of the tools utilized by the threat actor, the different attack channels, and their malware distribution techniques uncovered this campaign.[emaillocker id="1283"]

The attackers use a variety of techniques to spread their malware to their targets, including social engineering, phishing emails purporting to be from Energias de Portugal (EDP) and the Portuguese Tax and Customs Authority (AT), and malicious websites that look like these government organizations. In every instance, the infection initiates with the execution of an obfuscated VB script that downloads and runs a malware loader, which then waits five seconds before loading two variations of the 'PeepingTitle' backdoor onto the victim's PC. The malicious code in the VB scripts is disguised so that it is dispersed throughout a sizable number of code comments, most of which are pasted text from publicly accessible code repositories. The analysts add that these scripts' functions are to divert users' attention away from downloading malware while also stealing their EDP and AT credentials by sending them to the connected fake portals.

PeepingTitle is a Delphi-written malware with an April 2023 collection date. The attackers drop two variations, one for capturing the victim's screen and the other for monitoring windows and the user's activities with them. Also, after registering the target system and delivering reconnaissance details to the attackers, the second variation can fetch further payloads. When the virus discovers a window that matches a hardcoded list of financial institutions, it captures all user input (including credentials) and sends it to the threat actor's C2 server. PeepingTitle may also take screenshots, stop processes on the host, modify its monitoring interval configuration on the fly, and use Windows "rundll32" to stage payloads from executables or DLL files.

Operation Magalenha underscores the ongoing danger posed by Brazilian threat actors. Their adaptability and ability to refine their tactics and malware demonstrate their effectiveness in targeting organizations and individuals. Their focus on Portuguese- and Spanish-speaking countries reveals their understanding of local financial systems and their commitment to tailored attacks.

 

 Threat Profile:

Tactic Technique Id Technique
Initial Access T1566 Phishing
Execution  T1059 Command and Scripting Interpreter
 T1204 User Execution
Defense Evasion T1027 Obfuscated Files or Information
T1036 Masquerading
T1218 System Binary Proxy Execution
Credential Access T1111 Multi-Factor Authentication Interception
Discovery T1010 Application Window Discovery
Collection T1113 Screen Capture
T1560 Archive Collected Data
Command and Control T1105 Ingress Tool Transfer
Exfiltration T1041 Exfiltration Over C2 Channel
Impact T1486 Data Encrypted for Impact

 

References:

The following reports contain further technical details:

https://www.bleepingcomputer.com/news/security/operation-magalenha-targets-credentials-of-30-portuguese-banks/

[/emaillocker]
crossmenu