Casbaneiro is targeting online banking users in Latin America through phishing messages that look like urgent invoices or legal notices.
The campaign uses personalised PDF lures to push recipients toward a malicious download chain, putting email data, banking activity and system details at risk.
The Windows-focused operation is designed to stay quiet until it matters most. After gaining a foothold, it waits for a victim to browse a targeted bank site, then contacts its command infrastructure and can begin actions intended to support fraud.
Fortinet researchers identified the activity in August 2026 and tracked victims in Argentina, Peru, Colombia and Mexico. The findings show how regional filtering, staged downloads and timed network traffic can make a banking Trojan harder to spot in routine security reviews.
Fortinet said in a report shared with Cyber Security News (CSN) that the campaign sends stolen information to separate servers and uses a deliberately expected HTTP 403 response to confuse analysis.
The approach creates a risk beyond one compromised account, because harvested contacts and email details can support later attacks.
Hackers Deploy Casbaneiro Banking Trojan
The attack begins with an email and PDF that creates urgency around an invoice or supposed legal proceeding. The documents may display the recipient’s email address, a simple trick that adds credibility.
Similar deception appears in reports on weaponized PDF threats, where a familiar document becomes the first step toward malware delivery.

A link first checks the visitor’s IP address. Visitors outside the selected countries are redirected to legitimate sites such as Google or YouTube, while targets are served a page that silently downloads a Base64-encoded ZIP archive.
That location check limits exposure and reduces the chance that researchers will receive the same malicious content.
Inside the archive, an HTA file fetches further script content and checks the device for analysis environments and approved operating-system languages.
If the system passes, it downloads a legitimate AutoIt interpreter, a compiled script and a compressed component separately. This staged approach resembles the delivery patterns described in AutoIt loader abuse, which can help malware hide its combined purpose.
The loader shows a fake Windows service window, extracts the final program and injects it into RegSvcs.exe or, when unavailable, mobsync.exe.
It also creates a Startup shortcut for persistence. These steps can leave an infected user unaware that the visible service prompt is a decoy rather than a system task.
Data Theft and Evasion
Once active, Casbaneiro decrypts its configuration, collects address-book entries and Outlook sender and recipient details, and transmits the information without encryption.
It builds an identifier from the computer name, user name and executable name, then uses a hash of that value to track activity and avoid repeating some actions.

The Trojan does not immediately use its main command channel. It waits until the victim visits one of the targeted bank websites, then sends system information and accepts commands for keyboard control, clipboard pasting, file execution and command execution.
Its fake-window functions can also target specified banks, increasing the danger during an active online banking session.
A second server returns HTTP 403 when it receives Base64-encoded victim data. Rather than signalling failure, that response is part of the process; any other status makes the malware retry.
The campaign also sends different information to different servers and uses malformed HTTP requests, complicating network investigations. Its bank-triggered behaviour echoes Ousaban banking malware activity, another campaign that waits for victims to open selected banking sites.
Organisations should treat unexpected invoice and legal-notice PDFs as suspicious, verify requests through a separate channel and block execution of downloaded HTA files where possible.
Security teams should monitor for unusual AutoIt use, Startup-folder shortcuts, browser-triggered outbound traffic and failed-looking 403 communications.
Employee training and prompt reporting remain important, particularly for messages designed to create urgency. Readers can review banking Trojan campaign tactics to recognise related warning signs.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| PDF SHA-256 | 6bb4372d0d02ec87b76409f69d445a93910964f8db457bafafb97a011da59e73 |
Malicious PDF lure |
| PDF SHA-256 | 40d253480f752805e58c21266e40afe99afc96feea0d355732af5bea459db1dd |
Malicious PDF lure |
| PDF SHA-256 | bf92a287a3d79afb73a3f2d38877ec37c22a9f4a7d6ac2e0385472298f384fc8 |
Malicious PDF lure |
| PDF SHA-256 | 943d63ace373ee50d074daf84d357f8e5e62ff91c829d87f566bee453d715280 |
Malicious PDF lure |
| PDF SHA-256 | 711c0aa8cde078aa349fb329e3e44e4272ea66a5e651ad8a64893c76a725c859 |
Malicious PDF lure |
| PDF SHA-256 | d910e08a11a4f6f764e7495f4602a00b6024ca6e1b70fe30ba3752b881574365 |
Malicious PDF lure |
| PDF SHA-256 | 47d321c1a232e5cdd1e39a06dadbd79114dc1a2f0f8eac289e6b653a5d126f95 |
Malicious PDF lure |
| PDF SHA-256 | d13ad6fc5fda54e65f1214e554a5123126ac7b3ce6db57566ed7bd0e92d03d85 |
Malicious PDF lure |
| PDF SHA-256 | d04f68079ca90c65223a907f23fae5d068904a2145348b953b1d06e2eaf0bf2c |
Malicious PDF lure |
| PDF SHA-256 | 1b4d5c95f4fc037ca3c359cea5ca2da1285bbadab12bcdcb47f3dad8bc6fa8ed |
Malicious PDF lure |
| PDF SHA-256 | 62ef39ec29966d71c8254f68bd5e320cf24a042d76c12dbafdcc0766861827c5 |
Malicious PDF lure |
| PDF SHA-256 | 1f1a89bef73e4866a198a08e750f96348ce2b82816a8353e9a8a574bfde5f491 |
Malicious PDF lure |
| PDF SHA-256 | ea8af591fe2d605c82bb7831d2ebdfb17cb2659880e1a8a7b0a2dd851dc5e7a3 |
Malicious PDF lure |
| PDF SHA-256 | 0b4d962eef2d06abfe08a8cd0b15edd224d4fae0b57d708aebd77d99667616d5 |
Malicious PDF lure |
| PDF SHA-256 | c521b3a189b0089a2558aa4e42bd9fb5558e1b17917e2e183a4bd9cbcb2ed77e |
Malicious PDF lure |
| PDF SHA-256 | 0849a6b87fbef25089ad0be746f84047b080ba81898a8614da43d4ab60ef735a |
Malicious PDF lure |
| Email SHA-256 | debe871710268e7bb770b72c6772f2e0b8bd40a22b2eabf4b6556ea ba2d71057 |
Phishing email artifact |
| Email SHA-256 | eaec8c6950f394ad5dcd271aa86f08cb2b8374203ecc67015af7ca6 057244390 |
Phishing email artifact |
| Email SHA-256 | 995b1156562150c15970aa2d6b27f0b442d758594d820ec09d53d5 e861fac457 |
Phishing email artifact |
| Email SHA-256 | 918dd413cceed3b8aeaa79e45d9d7b2030d73e2affa4339b8f9d04 3d08844f62 |
Phishing email artifact |
| Email SHA-256 | be5a110ee72ebcf1b7d9e155308a8abc606bd446f8aec1a9f33cd06c a0f3c056 |
Phishing email artifact |
| Email SHA-256 | dc62e645589463a61e6ac562d034a9de4ed897714389eb6b87bb0 2f0bd59d565 |
Phishing email artifact |
| HTA SHA-256 | 4302586202234cdf1ca058fd3c62be0050c8155ed113f3f62337d756e6915044 |
HTA downloader |
| HTA SHA-256 | 85767416f8d1e73833ccaa193263d1198857308b3a1185e6f4ebc4164db8584f |
HTA downloader |
| HTA SHA-256 | f1aa14ebfd2da477edba94b34f09f775485688b5958d82fcb072a837e27e246b |
HTA downloader |
| HTA SHA-256 | c477bdfae91e3df9be29e9eeba785467aff294f5250c2eed406765032cb68756 |
HTA downloader |
| HTA SHA-256 | 6e6bd2f7566ffa52d52fa9d5f048bbb9246d3d50110c6b0c248919ad796c6fd4 |
HTA downloader |
| HTA SHA-256 | 4540c3af3b1d8c52256f4580dd4d002fadb8c5ff4e32e6a41fdf508455c5b697 |
HTA downloader |
| HTA SHA-256 | 92a1428e125f33de012c7f52fb0827be3d7e90e38a0e38083181f8c3312adc9c |
HTA downloader |
| HTA SHA-256 | e57409c5e1f8287900c1c3b3e8c099cef537a02949315eb768c88906b0c65add |
HTA downloader |
| HTA SHA-256 | 5a76669ec410d0b3e21112a4a6fd3207976b299ee27c5fc3d42f2673170ab95e |
HTA downloader |
| HTA SHA-256 | 8092b9de455463296898fcaf8c9955d1c00dae6812c03bba019edf9c059ece33 |
HTA downloader |
| HTA SHA-256 | 99fcabf7c996d6ec077ccd745a158a3a395403d6a3df9d8da179f3cd5faf81b1 |
HTA downloader |
| HTA SHA-256 | 875e8d4137e1016b4be869e36e00a9414e89902fd5592a2fb881ebb0e4bd2f8b |
HTA downloader |
| HTA SHA-256 | bd724bbb27f9a71fd44f1c334b003541761071655fa585b64eed3bd78fc28e01 |
HTA downloader |
| HTA SHA-256 | a42daeca71a6bdc79fd66b8b6ee413562abf7f72ef093292c86c1e9e7c2be456 |
HTA downloader |
| HTA SHA-256 | 7e04e86c07213fed7bebccd9953818b102b1b25b78e5f3707e81bad5054cf4e8 |
HTA downloader |
| HTA SHA-256 | 6547736c31dabb5bef2a290b32a72bf63b5c42dd2a33b5a6520159b41c43b093 |
HTA downloader |
| HTA SHA-256 | 51503ce1373c7fa72a1da5c5c4b30f88c8224686669ba4b64196591414fdc64c |
HTA downloader |
| HTA SHA-256 | 5b3c2442831d4844ea6b86942f1a0ba27170018382cbc362343db63717d0ff02 |
HTA downloader |
| HTA SHA-256 | 71dea06c2271a46fc2fd6092e2ba0c2f5a2cf5ca8f955ee3375e3ca66a5dc52b |
HTA downloader |
| Domain | 128[.]200[.]178[.]68[.]host[.]secureserver[.]net |
Campaign infrastructure |
| Domain | 13[.]189[.]202[.]64[.]host[.]secureserver[.]net |
Campaign infrastructure |
| Domain | 116[.]181[.]62[.]50[.]host[.]secureserver[.]net |
Campaign infrastructure |
| Domain | 48[.]178[.]169[.]192[.]host[.]secureserver[.]net |
Campaign infrastructure |
| Domain | 115[.]201[.]178[.]68[.]host[.]secureserver[.]net |
Campaign infrastructure |
| Domain | 181[.]202[.]178[.]68[.]host[.]secureserver[.]net |
Campaign infrastructure |
| Domain | 135[.]201[.]178[.]68[.]host[.]secureserver[.]net |
Campaign infrastructure |
| Domain | 85[.]182[.]62[.]50[.]host[.]secureserver[.]net |
Campaign infrastructure |
| Domain | 162[.]201[.]178[.]68[.]host[.]secureserver[.]net |
Campaign infrastructure |
| Domain | 129[.]202[.]178[.]68[.]host[.]secureserver[.]net |
Campaign infrastructure |
| Domain | 76[.]180[.]62[.]50[.]host[.]secureserver[.]net |
Campaign infrastructure |
| Domain | gexwalltool[.]com |
Campaign infrastructure |
| Domain | x-wolverine[.]servebbs[.]com |
Campaign infrastructure |
| IP address | 72[.]167[.]48[.]63 |
Campaign infrastructure |
| IP address | 209[.]99[.]188[.]28 |
Campaign infrastructure |
| AutoIt script SHA-256 | fc820eeb054c781693eca78fed1c418f12b27da2c7c7e73281eb07b25cc7d910 |
AutoIt loader component |
| AutoIt script SHA-256 | f76d09cbd455ce18765591b9efa3bde0d31358b6321f7a10fc2e04f65d7407ba |
AutoIt loader component |
| Casbaneiro payload SHA-256 | 7de637539159dc17ceedb0aae783930ee68639b6d8036ef8147027c5ebca3fc8 |
Casbaneiro payload |
| Cryptocurrency address | 0xb4c12078448fdef1f8881a55aab5c81fa194095c |
Embedded cryptocurrency address |
| Cryptocurrency address | bc1q7jt45630rw346729vk5cuatvfyvhfv0330u2p6 |
Embedded cryptocurrency address |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.
The post Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites appeared first on Cyber Security News.
