Summary:
An offensive campaign called "Operation Magalenha," a Brazilian hacker organization has been focusing on 30 Portuguese public and private financial institutions since 2021. Targeted companies include, among others, ActivoBank, Caixa Geral de Depósitos, CaixaBank, Citibanamex, Santander, Millennium BCP, ING, Banco BPI, and Novobanco. An analysis of the tools utilized by the threat actor, the different attack channels, and their malware distribution techniques uncovered this campaign.[/subscribe_to_unlock_form]
Summary:
An offensive campaign called "Operation Magalenha," a Brazilian hacker organization has been focusing on 30 Portuguese public and private financial institutions since 2021. Targeted companies include, among others, ActivoBank, Caixa Geral de Depósitos, CaixaBank, Citibanamex, Santander, Millennium BCP, ING, Banco BPI, and Novobanco. An analysis of the tools utilized by the threat actor, the different attack channels, and their malware distribution techniques uncovered this campaign.[emaillocker id="1283"]
The attackers use a variety of techniques to spread their malware to their targets, including social engineering, phishing emails purporting to be from Energias de Portugal (EDP) and the Portuguese Tax and Customs Authority (AT), and malicious websites that look like these government organizations. In every instance, the infection initiates with the execution of an obfuscated VB script that downloads and runs a malware loader, which then waits five seconds before loading two variations of the 'PeepingTitle' backdoor onto the victim's PC. The malicious code in the VB scripts is disguised so that it is dispersed throughout a sizable number of code comments, most of which are pasted text from publicly accessible code repositories. The analysts add that these scripts' functions are to divert users' attention away from downloading malware while also stealing their EDP and AT credentials by sending them to the connected fake portals.
PeepingTitle is a Delphi-written malware with an April 2023 collection date. The attackers drop two variations, one for capturing the victim's screen and the other for monitoring windows and the user's activities with them. Also, after registering the target system and delivering reconnaissance details to the attackers, the second variation can fetch further payloads. When the virus discovers a window that matches a hardcoded list of financial institutions, it captures all user input (including credentials) and sends it to the threat actor's C2 server. PeepingTitle may also take screenshots, stop processes on the host, modify its monitoring interval configuration on the fly, and use Windows "rundll32" to stage payloads from executables or DLL files.
Operation Magalenha underscores the ongoing danger posed by Brazilian threat actors. Their adaptability and ability to refine their tactics and malware demonstrate their effectiveness in targeting organizations and individuals. Their focus on Portuguese- and Spanish-speaking countries reveals their understanding of local financial systems and their commitment to tailored attacks.
Threat Profile:
| Tactic | Technique Id | Technique |
| Initial Access | T1566 | Phishing |
| Execution | T1059 | Command and Scripting Interpreter |
| T1204 | User Execution | |
| Defense Evasion | T1027 | Obfuscated Files or Information |
| T1036 | Masquerading | |
| T1218 | System Binary Proxy Execution | |
| Credential Access | T1111 | Multi-Factor Authentication Interception |
| Discovery | T1010 | Application Window Discovery |
| Collection | T1113 | Screen Capture |
| T1560 | Archive Collected Data | |
| Command and Control | T1105 | Ingress Tool Transfer |
| Exfiltration | T1041 | Exfiltration Over C2 Channel |
| Impact | T1486 | Data Encrypted for Impact |
References:
The following reports contain further technical details:
[/emaillocker]