Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Casbaneiro is targeting online banking users in Latin America through phishing messages that look like urgent invoices or legal notices.

The campaign uses personalised PDF lures to push recipients toward a malicious download chain, putting email data, banking activity and system details at risk.

The Windows-focused operation is designed to stay quiet until it matters most. After gaining a foothold, it waits for a victim to browse a targeted bank site, then contacts its command infrastructure and can begin actions intended to support fraud.

Fortinet researchers identified the activity in August 2026 and tracked victims in Argentina, Peru, Colombia and Mexico. The findings show how regional filtering, staged downloads and timed network traffic can make a banking Trojan harder to spot in routine security reviews.

Fortinet said in a report shared with Cyber Security News (CSN) that the campaign sends stolen information to separate servers and uses a deliberately expected HTTP 403 response to confuse analysis.

The approach creates a risk beyond one compromised account, because harvested contacts and email details can support later attacks.

Hackers Deploy Casbaneiro Banking Trojan

The attack begins with an email and PDF that creates urgency around an invoice or supposed legal proceeding. The documents may display the recipient’s email address, a simple trick that adds credibility.

Similar deception appears in reports on weaponized PDF threats, where a familiar document becomes the first step toward malware delivery.

Attack flow (Source - Fortinet)
Attack flow (Source – Fortinet)

A link first checks the visitor’s IP address. Visitors outside the selected countries are redirected to legitimate sites such as Google or YouTube, while targets are served a page that silently downloads a Base64-encoded ZIP archive.

That location check limits exposure and reduces the chance that researchers will receive the same malicious content.

Inside the archive, an HTA file fetches further script content and checks the device for analysis environments and approved operating-system languages.

If the system passes, it downloads a legitimate AutoIt interpreter, a compiled script and a compressed component separately. This staged approach resembles the delivery patterns described in AutoIt loader abuse, which can help malware hide its combined purpose.

The loader shows a fake Windows service window, extracts the final program and injects it into RegSvcs.exe or, when unavailable, mobsync.exe.

It also creates a Startup shortcut for persistence. These steps can leave an infected user unaware that the visible service prompt is a decoy rather than a system task.

Data Theft and Evasion

Once active, Casbaneiro decrypts its configuration, collects address-book entries and Outlook sender and recipient details, and transmits the information without encryption.

It builds an identifier from the computer name, user name and executable name, then uses a hash of that value to track activity and avoid repeating some actions.

Phishing PDF files (Source - Fortinet)
Phishing PDF files (Source – Fortinet)

The Trojan does not immediately use its main command channel. It waits until the victim visits one of the targeted bank websites, then sends system information and accepts commands for keyboard control, clipboard pasting, file execution and command execution.

Its fake-window functions can also target specified banks, increasing the danger during an active online banking session.

A second server returns HTTP 403 when it receives Base64-encoded victim data. Rather than signalling failure, that response is part of the process; any other status makes the malware retry.

The campaign also sends different information to different servers and uses malformed HTTP requests, complicating network investigations. Its bank-triggered behaviour echoes Ousaban banking malware activity, another campaign that waits for victims to open selected banking sites.

Organisations should treat unexpected invoice and legal-notice PDFs as suspicious, verify requests through a separate channel and block execution of downloaded HTA files where possible.

Security teams should monitor for unusual AutoIt use, Startup-folder shortcuts, browser-triggered outbound traffic and failed-looking 403 communications.

Employee training and prompt reporting remain important, particularly for messages designed to create urgency. Readers can review banking Trojan campaign tactics to recognise related warning signs.

Indicators of compromise (IoCs):-

Type Indicator Description
PDF SHA-256 6bb4372d0d02ec87b76409f69d445a93910964f8db457bafafb97a011da59e73 Malicious PDF lure
PDF SHA-256 40d253480f752805e58c21266e40afe99afc96feea0d355732af5bea459db1dd Malicious PDF lure
PDF SHA-256 bf92a287a3d79afb73a3f2d38877ec37c22a9f4a7d6ac2e0385472298f384fc8 Malicious PDF lure
PDF SHA-256 943d63ace373ee50d074daf84d357f8e5e62ff91c829d87f566bee453d715280 Malicious PDF lure
PDF SHA-256 711c0aa8cde078aa349fb329e3e44e4272ea66a5e651ad8a64893c76a725c859 Malicious PDF lure
PDF SHA-256 d910e08a11a4f6f764e7495f4602a00b6024ca6e1b70fe30ba3752b881574365 Malicious PDF lure
PDF SHA-256 47d321c1a232e5cdd1e39a06dadbd79114dc1a2f0f8eac289e6b653a5d126f95 Malicious PDF lure
PDF SHA-256 d13ad6fc5fda54e65f1214e554a5123126ac7b3ce6db57566ed7bd0e92d03d85 Malicious PDF lure
PDF SHA-256 d04f68079ca90c65223a907f23fae5d068904a2145348b953b1d06e2eaf0bf2c Malicious PDF lure
PDF SHA-256 1b4d5c95f4fc037ca3c359cea5ca2da1285bbadab12bcdcb47f3dad8bc6fa8ed Malicious PDF lure
PDF SHA-256 62ef39ec29966d71c8254f68bd5e320cf24a042d76c12dbafdcc0766861827c5 Malicious PDF lure
PDF SHA-256 1f1a89bef73e4866a198a08e750f96348ce2b82816a8353e9a8a574bfde5f491 Malicious PDF lure
PDF SHA-256 ea8af591fe2d605c82bb7831d2ebdfb17cb2659880e1a8a7b0a2dd851dc5e7a3 Malicious PDF lure
PDF SHA-256 0b4d962eef2d06abfe08a8cd0b15edd224d4fae0b57d708aebd77d99667616d5 Malicious PDF lure
PDF SHA-256 c521b3a189b0089a2558aa4e42bd9fb5558e1b17917e2e183a4bd9cbcb2ed77e Malicious PDF lure
PDF SHA-256 0849a6b87fbef25089ad0be746f84047b080ba81898a8614da43d4ab60ef735a Malicious PDF lure
Email SHA-256 debe871710268e7bb770b72c6772f2e0b8bd40a22b2eabf4b6556ea ba2d71057 Phishing email artifact
Email SHA-256 eaec8c6950f394ad5dcd271aa86f08cb2b8374203ecc67015af7ca6 057244390 Phishing email artifact
Email SHA-256 995b1156562150c15970aa2d6b27f0b442d758594d820ec09d53d5 e861fac457 Phishing email artifact
Email SHA-256 918dd413cceed3b8aeaa79e45d9d7b2030d73e2affa4339b8f9d04 3d08844f62 Phishing email artifact
Email SHA-256 be5a110ee72ebcf1b7d9e155308a8abc606bd446f8aec1a9f33cd06c a0f3c056 Phishing email artifact
Email SHA-256 dc62e645589463a61e6ac562d034a9de4ed897714389eb6b87bb0 2f0bd59d565 Phishing email artifact
HTA SHA-256 4302586202234cdf1ca058fd3c62be0050c8155ed113f3f62337d756e6915044 HTA downloader
HTA SHA-256 85767416f8d1e73833ccaa193263d1198857308b3a1185e6f4ebc4164db8584f HTA downloader
HTA SHA-256 f1aa14ebfd2da477edba94b34f09f775485688b5958d82fcb072a837e27e246b HTA downloader
HTA SHA-256 c477bdfae91e3df9be29e9eeba785467aff294f5250c2eed406765032cb68756 HTA downloader
HTA SHA-256 6e6bd2f7566ffa52d52fa9d5f048bbb9246d3d50110c6b0c248919ad796c6fd4 HTA downloader
HTA SHA-256 4540c3af3b1d8c52256f4580dd4d002fadb8c5ff4e32e6a41fdf508455c5b697 HTA downloader
HTA SHA-256 92a1428e125f33de012c7f52fb0827be3d7e90e38a0e38083181f8c3312adc9c HTA downloader
HTA SHA-256 e57409c5e1f8287900c1c3b3e8c099cef537a02949315eb768c88906b0c65add HTA downloader
HTA SHA-256 5a76669ec410d0b3e21112a4a6fd3207976b299ee27c5fc3d42f2673170ab95e HTA downloader
HTA SHA-256 8092b9de455463296898fcaf8c9955d1c00dae6812c03bba019edf9c059ece33 HTA downloader
HTA SHA-256 99fcabf7c996d6ec077ccd745a158a3a395403d6a3df9d8da179f3cd5faf81b1 HTA downloader
HTA SHA-256 875e8d4137e1016b4be869e36e00a9414e89902fd5592a2fb881ebb0e4bd2f8b HTA downloader
HTA SHA-256 bd724bbb27f9a71fd44f1c334b003541761071655fa585b64eed3bd78fc28e01 HTA downloader
HTA SHA-256 a42daeca71a6bdc79fd66b8b6ee413562abf7f72ef093292c86c1e9e7c2be456 HTA downloader
HTA SHA-256 7e04e86c07213fed7bebccd9953818b102b1b25b78e5f3707e81bad5054cf4e8 HTA downloader
HTA SHA-256 6547736c31dabb5bef2a290b32a72bf63b5c42dd2a33b5a6520159b41c43b093 HTA downloader
HTA SHA-256 51503ce1373c7fa72a1da5c5c4b30f88c8224686669ba4b64196591414fdc64c HTA downloader
HTA SHA-256 5b3c2442831d4844ea6b86942f1a0ba27170018382cbc362343db63717d0ff02 HTA downloader
HTA SHA-256 71dea06c2271a46fc2fd6092e2ba0c2f5a2cf5ca8f955ee3375e3ca66a5dc52b HTA downloader
Domain 128[.]200[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure
Domain 13[.]189[.]202[.]64[.]host[.]secureserver[.]net Campaign infrastructure
Domain 116[.]181[.]62[.]50[.]host[.]secureserver[.]net Campaign infrastructure
Domain 48[.]178[.]169[.]192[.]host[.]secureserver[.]net Campaign infrastructure
Domain 115[.]201[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure
Domain 181[.]202[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure
Domain 135[.]201[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure
Domain 85[.]182[.]62[.]50[.]host[.]secureserver[.]net Campaign infrastructure
Domain 162[.]201[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure
Domain 129[.]202[.]178[.]68[.]host[.]secureserver[.]net Campaign infrastructure
Domain 76[.]180[.]62[.]50[.]host[.]secureserver[.]net Campaign infrastructure
Domain gexwalltool[.]com Campaign infrastructure
Domain x-wolverine[.]servebbs[.]com Campaign infrastructure
IP address 72[.]167[.]48[.]63 Campaign infrastructure
IP address 209[.]99[.]188[.]28 Campaign infrastructure
AutoIt script SHA-256 fc820eeb054c781693eca78fed1c418f12b27da2c7c7e73281eb07b25cc7d910 AutoIt loader component
AutoIt script SHA-256 f76d09cbd455ce18765591b9efa3bde0d31358b6321f7a10fc2e04f65d7407ba AutoIt loader component
Casbaneiro payload SHA-256 7de637539159dc17ceedb0aae783930ee68639b6d8036ef8147027c5ebca3fc8 Casbaneiro payload
Cryptocurrency address 0xb4c12078448fdef1f8881a55aab5c81fa194095c Embedded cryptocurrency address
Cryptocurrency address bc1q7jt45630rw346729vk5cuatvfyvhfv0330u2p6 Embedded cryptocurrency address

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.

The post Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites appeared first on Cyber Security News.