FortiGuard Details Casbaneiro Banking Trojan Campaign Targeting Latin America

Summary
FortiGuard describes a Casbaneiro campaign targeting Latin American users with phishing lures and a multi-stage Windows infection chain. The malware steals email data and delays command-and-control activity until victims visit targeted banking sites.
Key points
- Observed in August 2026, the campaign targeted users in Argentina, Peru, Colombia, and Mexico with phishing emails and PDFs posing as invoices or legal notices.
- A geofenced webpage delivers a ZIP containing an HTA downloader; an AutoIt loader then injects Casbaneiro into RegSvcs.exe or, if unavailable, mobsync.exe.
- The infection chain checks for sandbox indicators and approved OS languages, uses randomly named files, and creates a Startup-folder shortcut for persistence.
- Casbaneiro collects address-book contacts and Outlook sender and recipient information, sending stolen data unencrypted to separate servers.
- The malware uses a server response of HTTP 403 and only begins certain C2 communications when a victim visits a targeted banking website, complicating analysis.
- It supports keyboard and clipboard control, file and command execution, and fake banking windows; malformed HTTP requests may hinder traffic inspection.
- FortiGuard reports detection by its antivirus products and provides file, domain, IP, and cryptocurrency-address indicators.
Article Details
- Attack Vectors
- Phishing emails and PDF files use fake invoices and legal notices to induce victims to click malicious links.
- A geofenced webpage downloads a Base64-encoded ZIP archive through JavaScript for visitors in the targeted region and redirects other visitors to legitimate websites.
- An HTA file retrieves an external script package, which downloads an AutoIt interpreter, a compiled AutoIt script, and a compressed payload separately.
- The AutoIt loader injects the final Casbaneiro payload into RegSvcs.exe, or into mobsync.exe if RegSvcs.exe does not exist.
- Casbaneiro sends collected Outlook information to an exfiltration endpoint and initiates C2 communication when the victim visits a targeted banking website.
- Defensive Notes
- Fortinet reports FortiGuard Antivirus detections PDF/Phishing.5BB0!tr, JS/Phishing.IBP!tr, and W32/Casbaneiro.EN!tr.spy.
- Fortinet states that FortiGate, FortiMail, FortiClient, and FortiEDR customers with up-to-date FortiGuard AntiVirus protections are protected.
- Fortinet reports that FortiMail recognizes the phishing email as “virus detected” and recommends phishing-awareness training.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | gexwalltool[.]com | Domain listed in the report’s threat-infrastructure IOCs. |
| HOSTNAME | 115[.]201[.]178[.]68[.]host[.]secureserver[.]net | Hostname listed in the report’s threat-infrastructure IOCs. |
| HOSTNAME | 116[.]181[.]62[.]50[.]host[.]secureserver[.]net | Hostname listed in the report’s threat-infrastructure IOCs. |
| HOSTNAME | 128[.]200[.]178[.]68[.]host[.]secureserver[.]net | Hostname listed in the report’s threat-infrastructure IOCs. |
| HOSTNAME | 129[.]202[.]178[.]68[.]host[.]secureserver[.]net | Hostname listed in the report’s threat-infrastructure IOCs. |
| HOSTNAME | 13[.]189[.]202[.]64[.]host[.]secureserver[.]net | Hostname listed in the report’s threat-infrastructure IOCs. |
| HOSTNAME | 135[.]201[.]178[.]68[.]host[.]secureserver[.]net | Hostname listed in the report’s threat-infrastructure IOCs. |
| HOSTNAME | 162[.]201[.]178[.]68[.]host[.]secureserver[.]net | Hostname listed in the report’s threat-infrastructure IOCs. |
| HOSTNAME | 181[.]202[.]178[.]68[.]host[.]secureserver[.]net | Hostname listed in the report’s threat-infrastructure IOCs. |
| HOSTNAME | 48[.]178[.]169[.]192[.]host[.]secureserver[.]net | Hostname listed in the report’s threat-infrastructure IOCs. |
| HOSTNAME | 76[.]180[.]62[.]50[.]host[.]secureserver[.]net | Hostname listed in the report’s threat-infrastructure IOCs. |
| HOSTNAME | 85[.]182[.]62[.]50[.]host[.]secureserver[.]net | Hostname listed in the report’s threat-infrastructure IOCs. |
| HOSTNAME | x-wolverine[.]servebbs[.]com | Hostname listed in the report’s threat-infrastructure IOCs. |
| IPV4 | 209[.]99[.]188[.]28 | IP address listed in the report’s threat-infrastructure IOCs. |
| IPV4 | 72[.]167[.]48[.]63 | IP address listed in the report’s threat-infrastructure IOCs. |
| SHA256 | 0849a6b87fbef25089ad0be746f84047b080ba81898a8614da43d4ab60ef735a | Phishing PDF hash listed as an IOC. |
| SHA256 | 0b4d962eef2d06abfe08a8cd0b15edd224d4fae0b57d708aebd77d99667616d5 | Phishing PDF hash listed as an IOC. |
| SHA256 | 1b4d5c95f4fc037ca3c359cea5ca2da1285bbadab12bcdcb47f3dad8bc6fa8ed | Phishing PDF hash listed as an IOC. |
| SHA256 | 1f1a89bef73e4866a198a08e750f96348ce2b82816a8353e9a8a574bfde5f491 | Phishing PDF hash listed as an IOC. |
| SHA256 | 40d253480f752805e58c21266e40afe99afc96feea0d355732af5bea459db1dd | Phishing PDF hash listed as an IOC. |
| SHA256 | 4302586202234cdf1ca058fd3c62be0050c8155ed113f3f62337d756e6915044 | Malicious HTA file hash listed as an IOC. |
| SHA256 | 4540c3af3b1d8c52256f4580dd4d002fadb8c5ff4e32e6a41fdf508455c5b697 | Malicious HTA file hash listed as an IOC. |
| SHA256 | 47d321c1a232e5cdd1e39a06dadbd79114dc1a2f0f8eac289e6b653a5d126f95 | Phishing PDF hash listed as an IOC. |
| SHA256 | 51503ce1373c7fa72a1da5c5c4b30f88c8224686669ba4b64196591414fdc64c | Malicious HTA file hash listed as an IOC. |
| SHA256 | 5a76669ec410d0b3e21112a4a6fd3207976b299ee27c5fc3d42f2673170ab95e | Malicious HTA file hash listed as an IOC. |
| SHA256 | 5b3c2442831d4844ea6b86942f1a0ba27170018382cbc362343db63717d0ff02 | Malicious HTA file hash listed as an IOC. |
| SHA256 | 62ef39ec29966d71c8254f68bd5e320cf24a042d76c12dbafdcc0766861827c5 | Phishing PDF hash listed as an IOC. |
| SHA256 | 6547736c31dabb5bef2a290b32a72bf63b5c42dd2a33b5a6520159b41c43b093 | Malicious HTA file hash listed as an IOC. |
| SHA256 | 6bb4372d0d02ec87b76409f69d445a93910964f8db457bafafb97a011da59e73 | Phishing PDF hash listed as an IOC. |
| SHA256 | 6e6bd2f7566ffa52d52fa9d5f048bbb9246d3d50110c6b0c248919ad796c6fd4 | Malicious HTA file hash listed as an IOC. |
| SHA256 | 711c0aa8cde078aa349fb329e3e44e4272ea66a5e651ad8a64893c76a725c859 | Phishing PDF hash listed as an IOC. |
| SHA256 | 71dea06c2271a46fc2fd6092e2ba0c2f5a2cf5ca8f955ee3375e3ca66a5dc52b | Malicious HTA file hash listed as an IOC. |
| SHA256 | 7de637539159dc17ceedb0aae783930ee68639b6d8036ef8147027c5ebca3fc8 | Casbaneiro payload hash listed as an IOC. |
| SHA256 | 7e04e86c07213fed7bebccd9953818b102b1b25b78e5f3707e81bad5054cf4e8 | Malicious HTA file hash listed as an IOC. |
| SHA256 | 8092b9de455463296898fcaf8c9955d1c00dae6812c03bba019edf9c059ece33 | Malicious HTA file hash listed as an IOC. |
| SHA256 | 85767416f8d1e73833ccaa193263d1198857308b3a1185e6f4ebc4164db8584f | Malicious HTA file hash listed as an IOC. |
| SHA256 | 875e8d4137e1016b4be869e36e00a9414e89902fd5592a2fb881ebb0e4bd2f8b | Malicious HTA file hash listed as an IOC. |
| SHA256 | 918dd413cceed3b8aeaa79e45d9d7b2030d73e2affa4339b8f9d043d08844f62 | Phishing email artifact hash listed as an IOC. |
| SHA256 | 92a1428e125f33de012c7f52fb0827be3d7e90e38a0e38083181f8c3312adc9c | Malicious HTA file hash listed as an IOC. |
| SHA256 | 943d63ace373ee50d074daf84d357f8e5e62ff91c829d87f566bee453d715280 | Phishing PDF hash listed as an IOC. |
| SHA256 | 995b1156562150c15970aa2d6b27f0b442d758594d820ec09d53d5e861fac457 | Phishing email artifact hash listed as an IOC. |
| SHA256 | 99fcabf7c996d6ec077ccd745a158a3a395403d6a3df9d8da179f3cd5faf81b1 | Malicious HTA file hash listed as an IOC. |
| SHA256 | a42daeca71a6bdc79fd66b8b6ee413562abf7f72ef093292c86c1e9e7c2be456 | Malicious HTA file hash listed as an IOC. |
| SHA256 | bd724bbb27f9a71fd44f1c334b003541761071655fa585b64eed3bd78fc28e01 | Malicious HTA file hash listed as an IOC. |
| SHA256 | be5a110ee72ebcf1b7d9e155308a8abc606bd446f8aec1a9f33cd06ca0f3c056 | Phishing email artifact hash listed as an IOC. |
| SHA256 | bf92a287a3d79afb73a3f2d38877ec37c22a9f4a7d6ac2e0385472298f384fc8 | Phishing PDF hash listed as an IOC. |
| SHA256 | c477bdfae91e3df9be29e9eeba785467aff294f5250c2eed406765032cb68756 | Malicious HTA file hash listed as an IOC. |
| SHA256 | c521b3a189b0089a2558aa4e42bd9fb5558e1b17917e2e183a4bd9cbcb2ed77e | Phishing PDF hash listed as an IOC. |
| SHA256 | d04f68079ca90c65223a907f23fae5d068904a2145348b953b1d06e2eaf0bf2c | Phishing PDF hash listed as an IOC. |
| SHA256 | d13ad6fc5fda54e65f1214e554a5123126ac7b3ce6db57566ed7bd0e92d03d85 | Phishing PDF hash listed as an IOC. |
| SHA256 | d910e08a11a4f6f764e7495f4602a00b6024ca6e1b70fe30ba3752b881574365 | Phishing PDF hash listed as an IOC. |
| SHA256 | dc62e645589463a61e6ac562d034a9de4ed897714389eb6b87bb02f0bd59d565 | Phishing email artifact hash listed as an IOC. |
| SHA256 | debe871710268e7bb770b72c6772f2e0b8bd40a22b2eabf4b6556eaba2d71057 | Phishing email artifact hash listed as an IOC. |
| SHA256 | e57409c5e1f8287900c1c3b3e8c099cef537a02949315eb768c88906b0c65add | Malicious HTA file hash listed as an IOC. |
| SHA256 | ea8af591fe2d605c82bb7831d2ebdfb17cb2659880e1a8a7b0a2dd851dc5e7a3 | Phishing PDF hash listed as an IOC. |
| SHA256 | eaec8c6950f394ad5dcd271aa86f08cb2b8374203ecc67015af7ca6057244390 | Phishing email artifact hash listed as an IOC. |
| SHA256 | f1aa14ebfd2da477edba94b34f09f775485688b5958d82fcb072a837e27e246b | Malicious HTA file hash listed as an IOC. |
| SHA256 | f76d09cbd455ce18765591b9efa3bde0d31358b6321f7a10fc2e04f65d7407ba | Compiled AutoIt script hash listed as an IOC. |
| SHA256 | fc820eeb054c781693eca78fed1c418f12b27da2c7c7e73281eb07b25cc7d910 | Compiled AutoIt script hash listed as an IOC. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationThe download page embeds a Base64-encoded ZIP archive, and Casbaneiro stores encrypted strings in fragments assembled at runtime.T1055 · Process InjectionThe AutoIt loader injects the final payload into RegSvcs.exe, or mobsync.exe if RegSvcs.exe is absent.T1059.007 · JavaScriptThe HTA retrieves an XML-based script package containing JScript that checks the environment and downloads later-stage components.T1071.001 · Web ProtocolsCasbaneiro uses HTTP requests for server communication, including C2 communication triggered by visits to targeted banking websites.T1114.001 · Local Email CollectionCasbaneiro collects email addresses from the victim’s address book and sender and recipient information from locally stored Microsoft Outlook emails.T1204.001 · Malicious LinkThe lures prompt recipients to click malicious links leading to the infection chain.T1497.001 · System ChecksThe JScript performs WMI-based sandbox checks and checks the OS language before continuing.T1547.001 · Registry Run Keys / Startup FolderThe downloader creates an LNK file in the Startup folder to run the AutoIt script through its interpreter.T1566.001 · Spearphishing AttachmentPhishing emails carry PDF lures themed around fake invoices and legal notices.
Malware
Vendors
Products
FortiClientFortiGate, FortiMail, FortiClient, and FortiEDR support the FortiGuard AntiVirus service.FortiEDRFortiGate, FortiMail, FortiClient, and FortiEDR support the FortiGuard AntiVirus service.FortiGateFortiGate, FortiMail, FortiClient, and FortiEDR support the FortiGuard AntiVirus service.FortiGuard AntivirusThe malware described in this report is detected and blocked by FortiGuard Antivirus as:FortiMailFortiGate, FortiMail, FortiClient, and FortiEDR support the FortiGuard AntiVirus service.FortiSandboxrecognizes the phishing email as “virus detected.” In addition, real-time anti-phishing provided by FortiSandbox embedded in Fortinet’s FortiMail, web filtering, and antivirus solutions provides advanced protectionMicrosoft OutlookThe malware collects email addresses from the victim’s address book, as well as sender and recipient information from emails stored in Microsoft Outlook.Microsoft WindowsAffected Platforms: Microsoft Windows
Tools
Countries
ArgentinaThe country code top-level domain in the documents further suggests a regional targeting strategy, with observed activity indicating a focus on Latin America, including Argentina, Peru, Colombia, and Mexico.ColombiaThe country code top-level domain in the documents further suggests a regional targeting strategy, with observed activity indicating a focus on Latin America, including Argentina, Peru, Colombia, and Mexico.MexicoThe country code top-level domain in the documents further suggests a regional targeting strategy, with observed activity indicating a focus on Latin America, including Argentina, Peru, Colombia, and Mexico.PeruThe country code top-level domain in the documents further suggests a regional targeting strategy, with observed activity indicating a focus on Latin America, including Argentina, Peru, Colombia, and Mexico.