FortiGuard Details Casbaneiro Banking Trojan Campaign Targeting Latin America

· Original article ↗

Summary

FortiGuard describes a Casbaneiro campaign targeting Latin American users with phishing lures and a multi-stage Windows infection chain. The malware steals email data and delays command-and-control activity until victims visit targeted banking sites.

Key points

  • Observed in August 2026, the campaign targeted users in Argentina, Peru, Colombia, and Mexico with phishing emails and PDFs posing as invoices or legal notices.
  • A geofenced webpage delivers a ZIP containing an HTA downloader; an AutoIt loader then injects Casbaneiro into RegSvcs.exe or, if unavailable, mobsync.exe.
  • The infection chain checks for sandbox indicators and approved OS languages, uses randomly named files, and creates a Startup-folder shortcut for persistence.
  • Casbaneiro collects address-book contacts and Outlook sender and recipient information, sending stolen data unencrypted to separate servers.
  • The malware uses a server response of HTTP 403 and only begins certain C2 communications when a victim visits a targeted banking website, complicating analysis.
  • It supports keyboard and clipboard control, file and command execution, and fake banking windows; malformed HTTP requests may hinder traffic inspection.
  • FortiGuard reports detection by its antivirus products and provides file, domain, IP, and cryptocurrency-address indicators.

Article Details

Attack Vectors
  • Phishing emails and PDF files use fake invoices and legal notices to induce victims to click malicious links.
  • A geofenced webpage downloads a Base64-encoded ZIP archive through JavaScript for visitors in the targeted region and redirects other visitors to legitimate websites.
  • An HTA file retrieves an external script package, which downloads an AutoIt interpreter, a compiled AutoIt script, and a compressed payload separately.
  • The AutoIt loader injects the final Casbaneiro payload into RegSvcs.exe, or into mobsync.exe if RegSvcs.exe does not exist.
  • Casbaneiro sends collected Outlook information to an exfiltration endpoint and initiates C2 communication when the victim visits a targeted banking website.
Defensive Notes
  • Fortinet reports FortiGuard Antivirus detections PDF/Phishing.5BB0!tr, JS/Phishing.IBP!tr, and W32/Casbaneiro.EN!tr.spy.
  • Fortinet states that FortiGate, FortiMail, FortiClient, and FortiEDR customers with up-to-date FortiGuard AntiVirus protections are protected.
  • Fortinet reports that FortiMail recognizes the phishing email as “virus detected” and recommends phishing-awareness training.

Indicators of compromise

TypeIndicatorContext
DOMAINgexwalltool[.]comDomain listed in the report’s threat-infrastructure IOCs.
HOSTNAME115[.]201[.]178[.]68[.]host[.]secureserver[.]netHostname listed in the report’s threat-infrastructure IOCs.
HOSTNAME116[.]181[.]62[.]50[.]host[.]secureserver[.]netHostname listed in the report’s threat-infrastructure IOCs.
HOSTNAME128[.]200[.]178[.]68[.]host[.]secureserver[.]netHostname listed in the report’s threat-infrastructure IOCs.
HOSTNAME129[.]202[.]178[.]68[.]host[.]secureserver[.]netHostname listed in the report’s threat-infrastructure IOCs.
HOSTNAME13[.]189[.]202[.]64[.]host[.]secureserver[.]netHostname listed in the report’s threat-infrastructure IOCs.
HOSTNAME135[.]201[.]178[.]68[.]host[.]secureserver[.]netHostname listed in the report’s threat-infrastructure IOCs.
HOSTNAME162[.]201[.]178[.]68[.]host[.]secureserver[.]netHostname listed in the report’s threat-infrastructure IOCs.
HOSTNAME181[.]202[.]178[.]68[.]host[.]secureserver[.]netHostname listed in the report’s threat-infrastructure IOCs.
HOSTNAME48[.]178[.]169[.]192[.]host[.]secureserver[.]netHostname listed in the report’s threat-infrastructure IOCs.
HOSTNAME76[.]180[.]62[.]50[.]host[.]secureserver[.]netHostname listed in the report’s threat-infrastructure IOCs.
HOSTNAME85[.]182[.]62[.]50[.]host[.]secureserver[.]netHostname listed in the report’s threat-infrastructure IOCs.
HOSTNAMEx-wolverine[.]servebbs[.]comHostname listed in the report’s threat-infrastructure IOCs.
IPV4209[.]99[.]188[.]28IP address listed in the report’s threat-infrastructure IOCs.
IPV472[.]167[.]48[.]63IP address listed in the report’s threat-infrastructure IOCs.
SHA2560849a6b87fbef25089ad0be746f84047b080ba81898a8614da43d4ab60ef735aPhishing PDF hash listed as an IOC.
SHA2560b4d962eef2d06abfe08a8cd0b15edd224d4fae0b57d708aebd77d99667616d5Phishing PDF hash listed as an IOC.
SHA2561b4d5c95f4fc037ca3c359cea5ca2da1285bbadab12bcdcb47f3dad8bc6fa8edPhishing PDF hash listed as an IOC.
SHA2561f1a89bef73e4866a198a08e750f96348ce2b82816a8353e9a8a574bfde5f491Phishing PDF hash listed as an IOC.
SHA25640d253480f752805e58c21266e40afe99afc96feea0d355732af5bea459db1ddPhishing PDF hash listed as an IOC.
SHA2564302586202234cdf1ca058fd3c62be0050c8155ed113f3f62337d756e6915044Malicious HTA file hash listed as an IOC.
SHA2564540c3af3b1d8c52256f4580dd4d002fadb8c5ff4e32e6a41fdf508455c5b697Malicious HTA file hash listed as an IOC.
SHA25647d321c1a232e5cdd1e39a06dadbd79114dc1a2f0f8eac289e6b653a5d126f95Phishing PDF hash listed as an IOC.
SHA25651503ce1373c7fa72a1da5c5c4b30f88c8224686669ba4b64196591414fdc64cMalicious HTA file hash listed as an IOC.
SHA2565a76669ec410d0b3e21112a4a6fd3207976b299ee27c5fc3d42f2673170ab95eMalicious HTA file hash listed as an IOC.
SHA2565b3c2442831d4844ea6b86942f1a0ba27170018382cbc362343db63717d0ff02Malicious HTA file hash listed as an IOC.
SHA25662ef39ec29966d71c8254f68bd5e320cf24a042d76c12dbafdcc0766861827c5Phishing PDF hash listed as an IOC.
SHA2566547736c31dabb5bef2a290b32a72bf63b5c42dd2a33b5a6520159b41c43b093Malicious HTA file hash listed as an IOC.
SHA2566bb4372d0d02ec87b76409f69d445a93910964f8db457bafafb97a011da59e73Phishing PDF hash listed as an IOC.
SHA2566e6bd2f7566ffa52d52fa9d5f048bbb9246d3d50110c6b0c248919ad796c6fd4Malicious HTA file hash listed as an IOC.
SHA256711c0aa8cde078aa349fb329e3e44e4272ea66a5e651ad8a64893c76a725c859Phishing PDF hash listed as an IOC.
SHA25671dea06c2271a46fc2fd6092e2ba0c2f5a2cf5ca8f955ee3375e3ca66a5dc52bMalicious HTA file hash listed as an IOC.
SHA2567de637539159dc17ceedb0aae783930ee68639b6d8036ef8147027c5ebca3fc8Casbaneiro payload hash listed as an IOC.
SHA2567e04e86c07213fed7bebccd9953818b102b1b25b78e5f3707e81bad5054cf4e8Malicious HTA file hash listed as an IOC.
SHA2568092b9de455463296898fcaf8c9955d1c00dae6812c03bba019edf9c059ece33Malicious HTA file hash listed as an IOC.
SHA25685767416f8d1e73833ccaa193263d1198857308b3a1185e6f4ebc4164db8584fMalicious HTA file hash listed as an IOC.
SHA256875e8d4137e1016b4be869e36e00a9414e89902fd5592a2fb881ebb0e4bd2f8bMalicious HTA file hash listed as an IOC.
SHA256918dd413cceed3b8aeaa79e45d9d7b2030d73e2affa4339b8f9d043d08844f62Phishing email artifact hash listed as an IOC.
SHA25692a1428e125f33de012c7f52fb0827be3d7e90e38a0e38083181f8c3312adc9cMalicious HTA file hash listed as an IOC.
SHA256943d63ace373ee50d074daf84d357f8e5e62ff91c829d87f566bee453d715280Phishing PDF hash listed as an IOC.
SHA256995b1156562150c15970aa2d6b27f0b442d758594d820ec09d53d5e861fac457Phishing email artifact hash listed as an IOC.
SHA25699fcabf7c996d6ec077ccd745a158a3a395403d6a3df9d8da179f3cd5faf81b1Malicious HTA file hash listed as an IOC.
SHA256a42daeca71a6bdc79fd66b8b6ee413562abf7f72ef093292c86c1e9e7c2be456Malicious HTA file hash listed as an IOC.
SHA256bd724bbb27f9a71fd44f1c334b003541761071655fa585b64eed3bd78fc28e01Malicious HTA file hash listed as an IOC.
SHA256be5a110ee72ebcf1b7d9e155308a8abc606bd446f8aec1a9f33cd06ca0f3c056Phishing email artifact hash listed as an IOC.
SHA256bf92a287a3d79afb73a3f2d38877ec37c22a9f4a7d6ac2e0385472298f384fc8Phishing PDF hash listed as an IOC.
SHA256c477bdfae91e3df9be29e9eeba785467aff294f5250c2eed406765032cb68756Malicious HTA file hash listed as an IOC.
SHA256c521b3a189b0089a2558aa4e42bd9fb5558e1b17917e2e183a4bd9cbcb2ed77ePhishing PDF hash listed as an IOC.
SHA256d04f68079ca90c65223a907f23fae5d068904a2145348b953b1d06e2eaf0bf2cPhishing PDF hash listed as an IOC.
SHA256d13ad6fc5fda54e65f1214e554a5123126ac7b3ce6db57566ed7bd0e92d03d85Phishing PDF hash listed as an IOC.
SHA256d910e08a11a4f6f764e7495f4602a00b6024ca6e1b70fe30ba3752b881574365Phishing PDF hash listed as an IOC.
SHA256dc62e645589463a61e6ac562d034a9de4ed897714389eb6b87bb02f0bd59d565Phishing email artifact hash listed as an IOC.
SHA256debe871710268e7bb770b72c6772f2e0b8bd40a22b2eabf4b6556eaba2d71057Phishing email artifact hash listed as an IOC.
SHA256e57409c5e1f8287900c1c3b3e8c099cef537a02949315eb768c88906b0c65addMalicious HTA file hash listed as an IOC.
SHA256ea8af591fe2d605c82bb7831d2ebdfb17cb2659880e1a8a7b0a2dd851dc5e7a3Phishing PDF hash listed as an IOC.
SHA256eaec8c6950f394ad5dcd271aa86f08cb2b8374203ecc67015af7ca6057244390Phishing email artifact hash listed as an IOC.
SHA256f1aa14ebfd2da477edba94b34f09f775485688b5958d82fcb072a837e27e246bMalicious HTA file hash listed as an IOC.
SHA256f76d09cbd455ce18765591b9efa3bde0d31358b6321f7a10fc2e04f65d7407baCompiled AutoIt script hash listed as an IOC.
SHA256fc820eeb054c781693eca78fed1c418f12b27da2c7c7e73281eb07b25cc7d910Compiled AutoIt script hash listed as an IOC.

MITRE ATT&CK

Malware

Vendors

Products

Tools

Countries

Industries

Related Articles