Threats Tagged 'autoit loader'
View all threats tagged with 'autoit loader'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'autoit loader'
Click on any threat for detailed analysis and mitigation recommendations
Casbaneiro is a banking Trojan active since August 2026, targeting Latin American users via phishing emails and malicious PDFs disguised as invoices and legal notices. It uses a multi-stage infection chain with HTA downloaders and AutoIt loaders, employing geofencing to restrict infection to specific countries. The malware uses sophisticated evasion techniques such as distributed data-receiving servers, deliberate HTTP 403 responses, and activation only on targeted banking websites. It steals email data, performs clipboard injection, and creates fake windows to facilitate fraud. The campaign specifically targets Argentina, Peru, Colombia, and Mexico, while avoiding systems using German, French, or English languages. The malware complicates detection by splitting stolen data across multiple servers and using malformed HTTP packets. Join the discussion | AlienVault OTX General | 09/10/2026, 17:27:46 UTC Added: 09/11/2026, 09:02:09 UTC |
Showing 1 to 1 of 1 result