Casbaneiro: A Banking Trojan with Distributed Data-Receiving Servers
Casbaneiro is a banking Trojan active since August 2026, targeting Latin American users via phishing emails and malicious PDFs disguised as invoices and legal notices. It uses a multi-stage infection chain with HTA downloaders and AutoIt loaders, employing geofencing to restrict infection to specific countries. The malware uses sophisticated evasion techniques such as distributed data-receiving servers, deliberate HTTP 403 responses, and activation only on targeted banking websites. It steals email data, performs clipboard injection, and creates fake windows to facilitate fraud. The campaign specifically targets Argentina, Peru, Colombia, and Mexico, while avoiding systems using German, French, or English languages. The malware complicates detection by splitting stolen data across multiple servers and using malformed HTTP packets.
AI Analysis
Technical Summary
Casbaneiro is a banking Trojan campaign observed in August 2026 that targets Latin American users through phishing emails and PDFs themed as fake invoices and legal notices. The infection chain involves HTA downloaders and AutoIt loaders. It uses geofencing to filter victims by IP address, activating only on targeted banking websites. The malware employs evasion techniques including distributed data-receiving servers, deliberate HTTP 403 responses to hinder analysis, and data splitting across multiple servers. It steals email data, performs clipboard injection, and creates fake windows to facilitate fraudulent activities. The campaign targets Argentina, Peru, Colombia, and Mexico, avoiding German, French, and English language systems.
Potential Impact
The malware enables credential theft and fraud by stealing email data, injecting clipboard content, and displaying fake windows to deceive victims. Its evasion techniques and distributed infrastructure complicate detection and analysis, increasing the risk of successful data theft and financial fraud in targeted Latin American countries.
Mitigation Recommendations
No vendor advisory or patch information is available for this malware. Mitigation should focus on user awareness to avoid phishing emails and suspicious attachments, network monitoring for unusual outbound connections to distributed servers, and endpoint detection solutions capable of identifying HTA downloaders and AutoIt loaders. Organizations in affected countries should apply targeted defenses against this threat.
Affected Countries
Argentina, Peru, Colombia, Mexico
Indicators of Compromise
- ip: 162.201.178.68
- hash: 4302586202234cdf1ca058fd3c62be0050c8155ed113f3f62337d756e6915044
- hash: 47d321c1a232e5cdd1e39a06dadbd79114dc1a2f0f8eac289e6b653a5d126f95
- hash: 51503ce1373c7fa72a1da5c5c4b30f88c8224686669ba4b64196591414fdc64c
- hash: 5a76669ec410d0b3e21112a4a6fd3207976b299ee27c5fc3d42f2673170ab95e
- hash: 62ef39ec29966d71c8254f68bd5e320cf24a042d76c12dbafdcc0766861827c5
- hash: 6bb4372d0d02ec87b76409f69d445a93910964f8db457bafafb97a011da59e73
- hash: 6e6bd2f7566ffa52d52fa9d5f048bbb9246d3d50110c6b0c248919ad796c6fd4
- hash: 711c0aa8cde078aa349fb329e3e44e4272ea66a5e651ad8a64893c76a725c859
- hash: 71dea06c2271a46fc2fd6092e2ba0c2f5a2cf5ca8f955ee3375e3ca66a5dc52b
- hash: 7de637539159dc17ceedb0aae783930ee68639b6d8036ef8147027c5ebca3fc8
- hash: 7e04e86c07213fed7bebccd9953818b102b1b25b78e5f3707e81bad5054cf4e8
- hash: 92a1428e125f33de012c7f52fb0827be3d7e90e38a0e38083181f8c3312adc9c
- hash: 995b1156562150c15970aa2d6b27f0b442d758594d820ec09d53d5e861fac457
- hash: 99fcabf7c996d6ec077ccd745a158a3a395403d6a3df9d8da179f3cd5faf81b1
- hash: bd724bbb27f9a71fd44f1c334b003541761071655fa585b64eed3bd78fc28e01
- hash: be5a110ee72ebcf1b7d9e155308a8abc606bd446f8aec1a9f33cd06ca0f3c056
- hash: bf92a287a3d79afb73a3f2d38877ec37c22a9f4a7d6ac2e0385472298f384fc8
- hash: c521b3a189b0089a2558aa4e42bd9fb5558e1b17917e2e183a4bd9cbcb2ed77e
- hash: d04f68079ca90c65223a907f23fae5d068904a2145348b953b1d06e2eaf0bf2c
- hash: debe871710268e7bb770b72c6772f2e0b8bd40a22b2eabf4b6556eaba2d71057
- hash: ea8af591fe2d605c82bb7831d2ebdfb17cb2659880e1a8a7b0a2dd851dc5e7a3
- hash: f1aa14ebfd2da477edba94b34f09f775485688b5958d82fcb072a837e27e246b
- hash: fc820eeb054c781693eca78fed1c418f12b27da2c7c7e73281eb07b25cc7d910
- ip: 115.201.178.68
- ip: 116.181.62.50
- ip: 128.200.178.68
- ip: 129.202.178.68
- ip: 135.201.178.68
- ip: 181.202.178.68
- ip: 209.99.188.28
- ip: 76.180.62.50
- ip: 85.182.62.50
- domain: gexwalltool.com
- domain: x-wolverine.servebbs.com
Casbaneiro: A Banking Trojan with Distributed Data-Receiving Servers
Description
Casbaneiro is a banking Trojan active since August 2026, targeting Latin American users via phishing emails and malicious PDFs disguised as invoices and legal notices. It uses a multi-stage infection chain with HTA downloaders and AutoIt loaders, employing geofencing to restrict infection to specific countries. The malware uses sophisticated evasion techniques such as distributed data-receiving servers, deliberate HTTP 403 responses, and activation only on targeted banking websites. It steals email data, performs clipboard injection, and creates fake windows to facilitate fraud. The campaign specifically targets Argentina, Peru, Colombia, and Mexico, while avoiding systems using German, French, or English languages. The malware complicates detection by splitting stolen data across multiple servers and using malformed HTTP packets.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Casbaneiro is a banking Trojan campaign observed in August 2026 that targets Latin American users through phishing emails and PDFs themed as fake invoices and legal notices. The infection chain involves HTA downloaders and AutoIt loaders. It uses geofencing to filter victims by IP address, activating only on targeted banking websites. The malware employs evasion techniques including distributed data-receiving servers, deliberate HTTP 403 responses to hinder analysis, and data splitting across multiple servers. It steals email data, performs clipboard injection, and creates fake windows to facilitate fraudulent activities. The campaign targets Argentina, Peru, Colombia, and Mexico, avoiding German, French, and English language systems.
Potential Impact
The malware enables credential theft and fraud by stealing email data, injecting clipboard content, and displaying fake windows to deceive victims. Its evasion techniques and distributed infrastructure complicate detection and analysis, increasing the risk of successful data theft and financial fraud in targeted Latin American countries.
Defensive Guidance
No vendor advisory or patch information is available for this malware. Mitigation should focus on user awareness to avoid phishing emails and suspicious attachments, network monitoring for unusual outbound connections to distributed servers, and endpoint detection solutions capable of identifying HTA downloaders and AutoIt loaders. Organizations in affected countries should apply targeted defenses against this threat.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.fortinet.com/blog/threat-research/casbaneiro-a-banking-trojan-with-distributed-data-receiving-servers"]
- Pulse Id
- 6aa2e892c25022290bdb9420
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip162.201.178.68 | — | |
ip115.201.178.68 | — | |
ip116.181.62.50 | — | |
ip128.200.178.68 | — | |
ip129.202.178.68 | — | |
ip135.201.178.68 | — | |
ip181.202.178.68 | — | |
ip209.99.188.28 | — | |
ip76.180.62.50 | — | |
ip85.182.62.50 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash4302586202234cdf1ca058fd3c62be0050c8155ed113f3f62337d756e6915044 | — | |
hash47d321c1a232e5cdd1e39a06dadbd79114dc1a2f0f8eac289e6b653a5d126f95 | — | |
hash51503ce1373c7fa72a1da5c5c4b30f88c8224686669ba4b64196591414fdc64c | — | |
hash5a76669ec410d0b3e21112a4a6fd3207976b299ee27c5fc3d42f2673170ab95e | — | |
hash62ef39ec29966d71c8254f68bd5e320cf24a042d76c12dbafdcc0766861827c5 | — | |
hash6bb4372d0d02ec87b76409f69d445a93910964f8db457bafafb97a011da59e73 | — | |
hash6e6bd2f7566ffa52d52fa9d5f048bbb9246d3d50110c6b0c248919ad796c6fd4 | — | |
hash711c0aa8cde078aa349fb329e3e44e4272ea66a5e651ad8a64893c76a725c859 | — | |
hash71dea06c2271a46fc2fd6092e2ba0c2f5a2cf5ca8f955ee3375e3ca66a5dc52b | — | |
hash7de637539159dc17ceedb0aae783930ee68639b6d8036ef8147027c5ebca3fc8 | — | |
hash7e04e86c07213fed7bebccd9953818b102b1b25b78e5f3707e81bad5054cf4e8 | — | |
hash92a1428e125f33de012c7f52fb0827be3d7e90e38a0e38083181f8c3312adc9c | — | |
hash995b1156562150c15970aa2d6b27f0b442d758594d820ec09d53d5e861fac457 | — | |
hash99fcabf7c996d6ec077ccd745a158a3a395403d6a3df9d8da179f3cd5faf81b1 | — | |
hashbd724bbb27f9a71fd44f1c334b003541761071655fa585b64eed3bd78fc28e01 | — | |
hashbe5a110ee72ebcf1b7d9e155308a8abc606bd446f8aec1a9f33cd06ca0f3c056 | — | |
hashbf92a287a3d79afb73a3f2d38877ec37c22a9f4a7d6ac2e0385472298f384fc8 | — | |
hashc521b3a189b0089a2558aa4e42bd9fb5558e1b17917e2e183a4bd9cbcb2ed77e | — | |
hashd04f68079ca90c65223a907f23fae5d068904a2145348b953b1d06e2eaf0bf2c | — | |
hashdebe871710268e7bb770b72c6772f2e0b8bd40a22b2eabf4b6556eaba2d71057 | — | |
hashea8af591fe2d605c82bb7831d2ebdfb17cb2659880e1a8a7b0a2dd851dc5e7a3 | — | |
hashf1aa14ebfd2da477edba94b34f09f775485688b5958d82fcb072a837e27e246b | — | |
hashfc820eeb054c781693eca78fed1c418f12b27da2c7c7e73281eb07b25cc7d910 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domaingexwalltool.com | — | |
domainx-wolverine.servebbs.com | — |
Threat ID: 6aa3c39191cc7f3848edf301
Added to database: 09/11/2026, 09:02:09 UTC
Last enriched: 09/11/2026, 09:18:48 UTC
Last updated: 09/11/2026, 16:00:06 UTC
Views: 18
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.