Skip to main content

Casbaneiro: A Banking Trojan with Distributed Data-Receiving Servers

0
Medium
Published: 09/10/2026 (09/10/2026, 17:27:46 UTC)
Source: AlienVault OTX General

Description

Casbaneiro is a banking Trojan active since August 2026, targeting Latin American users via phishing emails and malicious PDFs disguised as invoices and legal notices. It uses a multi-stage infection chain with HTA downloaders and AutoIt loaders, employing geofencing to restrict infection to specific countries. The malware uses sophisticated evasion techniques such as distributed data-receiving servers, deliberate HTTP 403 responses, and activation only on targeted banking websites. It steals email data, performs clipboard injection, and creates fake windows to facilitate fraud. The campaign specifically targets Argentina, Peru, Colombia, and Mexico, while avoiding systems using German, French, or English languages. The malware complicates detection by splitting stolen data across multiple servers and using malformed HTTP packets.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/11/2026, 09:18:48 UTC

Technical Analysis

Casbaneiro is a banking Trojan campaign observed in August 2026 that targets Latin American users through phishing emails and PDFs themed as fake invoices and legal notices. The infection chain involves HTA downloaders and AutoIt loaders. It uses geofencing to filter victims by IP address, activating only on targeted banking websites. The malware employs evasion techniques including distributed data-receiving servers, deliberate HTTP 403 responses to hinder analysis, and data splitting across multiple servers. It steals email data, performs clipboard injection, and creates fake windows to facilitate fraudulent activities. The campaign targets Argentina, Peru, Colombia, and Mexico, avoiding German, French, and English language systems.

Potential Impact

The malware enables credential theft and fraud by stealing email data, injecting clipboard content, and displaying fake windows to deceive victims. Its evasion techniques and distributed infrastructure complicate detection and analysis, increasing the risk of successful data theft and financial fraud in targeted Latin American countries.

Defensive Guidance

No vendor advisory or patch information is available for this malware. Mitigation should focus on user awareness to avoid phishing emails and suspicious attachments, network monitoring for unusual outbound connections to distributed servers, and endpoint detection solutions capable of identifying HTA downloaders and AutoIt loaders. Organizations in affected countries should apply targeted defenses against this threat.

Affected Countries

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.fortinet.com/blog/threat-research/casbaneiro-a-banking-trojan-with-distributed-data-receiving-servers"]
Pulse Id
6aa2e892c25022290bdb9420

Indicators of Compromise

Ip

ValueDescriptionCopy
ip162.201.178.68
ip115.201.178.68
ip116.181.62.50
ip128.200.178.68
ip129.202.178.68
ip135.201.178.68
ip181.202.178.68
ip209.99.188.28
ip76.180.62.50
ip85.182.62.50

Hash

ValueDescriptionCopy
hash4302586202234cdf1ca058fd3c62be0050c8155ed113f3f62337d756e6915044
hash47d321c1a232e5cdd1e39a06dadbd79114dc1a2f0f8eac289e6b653a5d126f95
hash51503ce1373c7fa72a1da5c5c4b30f88c8224686669ba4b64196591414fdc64c
hash5a76669ec410d0b3e21112a4a6fd3207976b299ee27c5fc3d42f2673170ab95e
hash62ef39ec29966d71c8254f68bd5e320cf24a042d76c12dbafdcc0766861827c5
hash6bb4372d0d02ec87b76409f69d445a93910964f8db457bafafb97a011da59e73
hash6e6bd2f7566ffa52d52fa9d5f048bbb9246d3d50110c6b0c248919ad796c6fd4
hash711c0aa8cde078aa349fb329e3e44e4272ea66a5e651ad8a64893c76a725c859
hash71dea06c2271a46fc2fd6092e2ba0c2f5a2cf5ca8f955ee3375e3ca66a5dc52b
hash7de637539159dc17ceedb0aae783930ee68639b6d8036ef8147027c5ebca3fc8
hash7e04e86c07213fed7bebccd9953818b102b1b25b78e5f3707e81bad5054cf4e8
hash92a1428e125f33de012c7f52fb0827be3d7e90e38a0e38083181f8c3312adc9c
hash995b1156562150c15970aa2d6b27f0b442d758594d820ec09d53d5e861fac457
hash99fcabf7c996d6ec077ccd745a158a3a395403d6a3df9d8da179f3cd5faf81b1
hashbd724bbb27f9a71fd44f1c334b003541761071655fa585b64eed3bd78fc28e01
hashbe5a110ee72ebcf1b7d9e155308a8abc606bd446f8aec1a9f33cd06ca0f3c056
hashbf92a287a3d79afb73a3f2d38877ec37c22a9f4a7d6ac2e0385472298f384fc8
hashc521b3a189b0089a2558aa4e42bd9fb5558e1b17917e2e183a4bd9cbcb2ed77e
hashd04f68079ca90c65223a907f23fae5d068904a2145348b953b1d06e2eaf0bf2c
hashdebe871710268e7bb770b72c6772f2e0b8bd40a22b2eabf4b6556eaba2d71057
hashea8af591fe2d605c82bb7831d2ebdfb17cb2659880e1a8a7b0a2dd851dc5e7a3
hashf1aa14ebfd2da477edba94b34f09f775485688b5958d82fcb072a837e27e246b
hashfc820eeb054c781693eca78fed1c418f12b27da2c7c7e73281eb07b25cc7d910

Domain

ValueDescriptionCopy
domaingexwalltool.com
domainx-wolverine.servebbs.com

Threat ID: 6aa3c39191cc7f3848edf301

Added to database: 09/11/2026, 09:02:09 UTC

Last enriched: 09/11/2026, 09:18:48 UTC

Last updated: 09/11/2026, 16:00:06 UTC

Views: 18

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses