Threats Tagged 'brazil'
View all threats tagged with 'brazil'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'brazil'
Click on any threat for detailed analysis and mitigation recommendations
In March 2026, threat actors leveraged AI-powered website builders to create typosquatting domains impersonating a Brazilian bank. The campaign employed ClickFix techniques, presenting victims with fake CAPTCHA and BSOD screens to trick them into executing malicious PowerShell commands. This delivered SmartRAT, a PowerShell-based banking trojan with capabilities including encrypted C2 communications, remote control of screen/keyboard/mouse, credential theft through keylogging and banking overlays, and QR code interception for transaction fraud. The malware establishes persistence via scheduled tasks and Windows services, and targets Brazilian financial institutions, payment platforms, and cryptocurrency exchanges. The threat actors' C2 panel contained critical authentication flaws allowing client-side bypass, suggesting deployment without adequate security review. Join the discussion | AlienVault OTX General | 06/17/2026, 18:20:54 UTC Added: 06/17/2026, 20:35:04 UTC |
BTMOB is an Android remote access trojan that evolved from SpySolr malware and poses significant threats beyond traditional banking trojans. The malware combines phishing-led delivery with an APK builder interface that enables rapid payload generation without coding skills. Distributed through fake app stores impersonating streaming services, cryptocurrency platforms, and government agencies, BTMOB abuses Android Accessibility Services to gain elevated permissions. Marketed as malware-as-a-service with a reported $5,000 lifetime license, it provides adversaries with capabilities to exfiltrate sensitive data, capture screenshots, record device activity, and establish remote control. The tool's customizable phishing lures have been adapted for specific regions, including campaigns impersonating Argentine tax authorities, making it a rapidly evolving threat with global reach. Join the discussion | AlienVault OTX General | 05/31/2026, 23:32:45 UTC Added: 06/01/2026, 08:48:35 UTC |
This report details the discovery and analysis of a Horabot malware campaign targeting primarily Mexican users. The attack chain begins with a fake CAPTCHA page leading to multiple stages of obfuscated scripts, ultimately delivering an AutoIT loader and a Delphi-based banking Trojan. The malware employs sophisticated encryption techniques, anti-VM checks, and a custom protocol for C2 communication. It also includes a spreader component written in PowerShell that harvests and exfiltrates email addresses to distribute phishing emails. The analysis reveals Brazilian Portuguese comments in the code, suggesting the threat actor's origin. The report provides detection opportunities including YARA rules and hunting queries to identify this threat. Join the discussion | AlienVault OTX General | 03/18/2026, 11:15:06 UTC Added: 03/18/2026, 16:42:29 UTC |
GoPix is an advanced persistent threat targeting Brazilian financial institutions and cryptocurrency users. It uses memory-only implants and obfuscated PowerShell scripts, evolving from previous RAT and ATS threats. The malware employs sophisticated techniques, including malvertising via Google Ads, man-in-the-middle attacks, and monitoring of Pix transactions and Boleto slips. GoPix bypasses security measures, maintains persistence, and uses robust cleanup mechanisms. It leverages multiple obfuscation layers and a stolen code signing certificate to evade detection. The threat actors carefully select victims, including financial bodies of state governments and large corporations, using legitimate anti-fraud services for targeted delivery. Join the discussion | AlienVault OTX General | 03/16/2026, 15:14:28 UTC Added: 03/16/2026, 18:28:34 UTC |
BeatBanker is a sophisticated Android malware campaign targeting Brazil. It spreads through phishing attacks using a fake Google Play Store website. The malware combines a cryptocurrency miner and a banking Trojan capable of hijacking devices and overlaying screens. It employs creative persistence mechanisms, including playing an inaudible audio loop. BeatBanker monitors device status, disguises itself as legitimate apps, and targets cryptocurrency transactions on Binance and Trust Wallet. Recent variants have replaced the banking module with the BTMOB remote administration tool, expanding its capabilities. The threat demonstrates advanced evasion techniques, uses Firebase Cloud Messaging for command and control, and targets multiple browsers for data collection. Victims are primarily located in Brazil, with some samples spreading via WhatsApp. Join the discussion | AlienVault OTX General | 03/10/2026, 12:26:22 UTC Added: 03/10/2026, 13:03:24 UTC |
The Water Saci campaign is a sophisticated malware operation primarily targeting Brazilian banking and cryptocurrency platforms via WhatsApp. It employs multi-format malware delivery using various scripting languages, including a shift from PowerShell to Python, likely enhanced by AI tools to evade detection and complicate analysis. The malware features aggressive anti-sandbox techniques, extensive backdoor capabilities, and persistence mechanisms. Although currently focused on Brazil, the use of WhatsApp as a propagation vector and targeting financial applications poses a potential risk to European organizations with ties to Brazilian markets or users. The campaign’s complexity and AI-enhanced development pipeline indicate a medium severity threat with significant evasion and persistence capabilities. Defenders should prioritize monitoring WhatsApp-based phishing attempts, scrutinize multi-format file attachments, and implement advanced behavioral detection to mitigate risks. Countries with strong economic or diaspora links to Brazil and high WhatsApp usage are more likely to be affected. Join the discussion | AlienVault OTX General | 12/02/2025, 14:44:59 UTC Added: 12/03/2025, 17:44:04 UTC |
A phishing campaign targeting Brazilian users spreads a banking trojan via WhatsApp Web by leveraging an open-source automation script. The attack starts with a malicious VBS script in a phishing email that downloads and executes an MSI installer and another VBS script. The second VBS installs Python and Selenium to inject malicious JavaScript into WhatsApp Web, enabling the malware to propagate by sending itself to the victim's contacts. The MSI drops an AutoIt script that monitors for Brazilian banking and cryptocurrency application windows and loads an encrypted payload into memory to evade detection. This payload specifically targets Brazilian financial institutions and cryptocurrency wallets. The campaign uses in-memory execution and automation to maintain stealth and persistence. No known exploits in the wild have been reported yet, and the campaign is currently assessed as medium severity. The attack is highly tailored to Brazilian users and financial targets but could pose risks if similar tactics spread elsewhere. Join the discussion | AlienVault OTX General | 11/24/2025, 12:02:31 UTC Added: 11/24/2025, 12:21:39 UTC |
A malware campaign targeting WhatsApp users primarily in Brazil uses WhatsApp's 'View Once' message feature to deliver malicious ZIP archives containing VBS or HTA files. These files execute PowerShell scripts to download additional payloads, including scripts that steal WhatsApp user data and an MSI installer deploying the Astaroth banking trojan. The campaign evolved from IMAP-based to HTTP-based command and control communication and leverages Selenium Chrome WebDriver and the WPPConnect JavaScript library to hijack WhatsApp Web sessions, steal session tokens and contacts, and distribute spam. Over 250 victims have been identified, with 95% located in Brazil and some impact noted in Austria. The attack enables credential theft, session hijacking, persistence, and financial fraud through banking trojan deployment. No CVE or known exploits in the wild are reported, and the campaign is rated medium severity. Defenders should focus on user awareness, endpoint detection of PowerShell and script execution, and monitoring for suspicious WhatsApp Web activity. Join the discussion | AlienVault OTX General | 11/20/2025, 19:42:41 UTC Added: 11/20/2025, 22:13:41 UTC |
This intelligence report examines the connection between two Brazilian banking trojans, Maverick and Coyote. The malware spreads through WhatsApp, using a multi-stage attack that begins with a malicious LNK file. Both trojans share similarities in their infection methods, targeting Brazilian users and banks. The attack chain involves obfuscated PowerShell commands, downloading additional payloads from command and control servers. The malware employs anti-analysis techniques and targets specific browsers. Persistence is achieved through a batch file in the startup folder. The report provides technical details, including code samples and infection chain analysis, as well as indicators of compromise for the identified malware campaign. Join the discussion | AlienVault OTX General | 11/12/2025, 09:45:13 UTC Added: 11/12/2025, 09:48:28 UTC |
The Brazilian Caminho loader is a sophisticated malware delivery mechanism active since March 2025, leveraging LSB steganography to hide . NET payloads within images hosted on legitimate platforms. It initiates infection via phishing emails containing malicious scripts that download these steganographic images. The loader executes payloads filelessly in memory and establishes persistence using scheduled tasks. Caminho operates as a Loader-as-a-Service, delivering multiple malware families such as Remcos RAT, Xworm, and Katz stealer across South America, Africa, and Eastern Europe. Its use of bulletproof hosting and Portuguese language artifacts indicates a Brazilian origin and professional operation. The campaign targets multiple industries opportunistically without a specific sector focus. The infection chain employs multiple advanced techniques including fileless execution, steganography, and obfuscation, complicating detection and mitigation efforts. European organizations, especially in Eastern Europe, face risks of data theft, espionage, and system compromise. Mitigation requires targeted email security, memory scanning, and monitoring of scheduled tasks for persistence. Join the discussion | AlienVault OTX General | 10/22/2025, 04:00:17 UTC Added: 10/22/2025, 12:09:03 UTC |
Showing 1 to 10 of 14 results