Cyber Security News

Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites

Casbaneiro is targeting online banking users in Latin America through phishing messages that look like urgent invoices or legal notices.

The campaign uses personalised PDF lures to push recipients toward a malicious download chain, putting email data, banking activity and system details at risk.

The Windows-focused operation is designed to stay quiet until it matters most. After gaining a foothold, it waits for a victim to browse a targeted bank site, then contacts its command infrastructure and can begin actions intended to support fraud.

Fortinet researchers identified the activity in August 2026 and tracked victims in Argentina, Peru, Colombia and Mexico. The findings show how regional filtering, staged downloads and timed network traffic can make a banking Trojan harder to spot in routine security reviews.

Fortinet said in a report shared with Cyber Security News (CSN) that the campaign sends stolen information to separate servers and uses a deliberately expected HTTP 403 response to confuse analysis.

The approach creates a risk beyond one compromised account, because harvested contacts and email details can support later attacks.

Hackers Deploy Casbaneiro Banking Trojan

The attack begins with an email and PDF that creates urgency around an invoice or supposed legal proceeding. The documents may display the recipient’s email address, a simple trick that adds credibility.

Similar deception appears in reports on weaponized PDF threats, where a familiar document becomes the first step toward malware delivery.

Attack flow (Source – Fortinet)

A link first checks the visitor’s IP address. Visitors outside the selected countries are redirected to legitimate sites such as Google or YouTube, while targets are served a page that silently downloads a Base64-encoded ZIP archive.

That location check limits exposure and reduces the chance that researchers will receive the same malicious content.

Inside the archive, an HTA file fetches further script content and checks the device for analysis environments and approved operating-system languages.

If the system passes, it downloads a legitimate AutoIt interpreter, a compiled script and a compressed component separately. This staged approach resembles the delivery patterns described in AutoIt loader abuse, which can help malware hide its combined purpose.

The loader shows a fake Windows service window, extracts the final program and injects it into RegSvcs.exe or, when unavailable, mobsync.exe.

It also creates a Startup shortcut for persistence. These steps can leave an infected user unaware that the visible service prompt is a decoy rather than a system task.

Data Theft and Evasion

Once active, Casbaneiro decrypts its configuration, collects address-book entries and Outlook sender and recipient details, and transmits the information without encryption.

It builds an identifier from the computer name, user name and executable name, then uses a hash of that value to track activity and avoid repeating some actions.

Phishing PDF files (Source – Fortinet)

The Trojan does not immediately use its main command channel. It waits until the victim visits one of the targeted bank websites, then sends system information and accepts commands for keyboard control, clipboard pasting, file execution and command execution.

Its fake-window functions can also target specified banks, increasing the danger during an active online banking session.

A second server returns HTTP 403 when it receives Base64-encoded victim data. Rather than signalling failure, that response is part of the process; any other status makes the malware retry.

The campaign also sends different information to different servers and uses malformed HTTP requests, complicating network investigations. Its bank-triggered behaviour echoes Ousaban banking malware activity, another campaign that waits for victims to open selected banking sites.

Organisations should treat unexpected invoice and legal-notice PDFs as suspicious, verify requests through a separate channel and block execution of downloaded HTA files where possible.

Security teams should monitor for unusual AutoIt use, Startup-folder shortcuts, browser-triggered outbound traffic and failed-looking 403 communications.

Employee training and prompt reporting remain important, particularly for messages designed to create urgency. Readers can review banking Trojan campaign tactics to recognise related warning signs.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
PDF SHA-2566bb4372d0d02ec87b76409f69d445a93910964f8db457bafafb97a011da59e73Malicious PDF lure
PDF SHA-25640d253480f752805e58c21266e40afe99afc96feea0d355732af5bea459db1ddMalicious PDF lure
PDF SHA-256bf92a287a3d79afb73a3f2d38877ec37c22a9f4a7d6ac2e0385472298f384fc8Malicious PDF lure
PDF SHA-256943d63ace373ee50d074daf84d357f8e5e62ff91c829d87f566bee453d715280Malicious PDF lure
PDF SHA-256711c0aa8cde078aa349fb329e3e44e4272ea66a5e651ad8a64893c76a725c859Malicious PDF lure
PDF SHA-256d910e08a11a4f6f764e7495f4602a00b6024ca6e1b70fe30ba3752b881574365Malicious PDF lure
PDF SHA-25647d321c1a232e5cdd1e39a06dadbd79114dc1a2f0f8eac289e6b653a5d126f95Malicious PDF lure
PDF SHA-256d13ad6fc5fda54e65f1214e554a5123126ac7b3ce6db57566ed7bd0e92d03d85Malicious PDF lure
PDF SHA-256d04f68079ca90c65223a907f23fae5d068904a2145348b953b1d06e2eaf0bf2cMalicious PDF lure
PDF SHA-2561b4d5c95f4fc037ca3c359cea5ca2da1285bbadab12bcdcb47f3dad8bc6fa8edMalicious PDF lure
PDF SHA-25662ef39ec29966d71c8254f68bd5e320cf24a042d76c12dbafdcc0766861827c5Malicious PDF lure
PDF SHA-2561f1a89bef73e4866a198a08e750f96348ce2b82816a8353e9a8a574bfde5f491Malicious PDF lure
PDF SHA-256ea8af591fe2d605c82bb7831d2ebdfb17cb2659880e1a8a7b0a2dd851dc5e7a3Malicious PDF lure
PDF SHA-2560b4d962eef2d06abfe08a8cd0b15edd224d4fae0b57d708aebd77d99667616d5Malicious PDF lure
PDF SHA-256c521b3a189b0089a2558aa4e42bd9fb5558e1b17917e2e183a4bd9cbcb2ed77eMalicious PDF lure
PDF SHA-2560849a6b87fbef25089ad0be746f84047b080ba81898a8614da43d4ab60ef735aMalicious PDF lure
Email SHA-256debe871710268e7bb770b72c6772f2e0b8bd40a22b2eabf4b6556ea ba2d71057Phishing email artifact
Email SHA-256eaec8c6950f394ad5dcd271aa86f08cb2b8374203ecc67015af7ca6 057244390Phishing email artifact
Email SHA-256995b1156562150c15970aa2d6b27f0b442d758594d820ec09d53d5 e861fac457Phishing email artifact
Email SHA-256918dd413cceed3b8aeaa79e45d9d7b2030d73e2affa4339b8f9d04 3d08844f62Phishing email artifact
Email SHA-256be5a110ee72ebcf1b7d9e155308a8abc606bd446f8aec1a9f33cd06c a0f3c056Phishing email artifact
Email SHA-256dc62e645589463a61e6ac562d034a9de4ed897714389eb6b87bb0 2f0bd59d565Phishing email artifact
HTA SHA-2564302586202234cdf1ca058fd3c62be0050c8155ed113f3f62337d756e6915044HTA downloader
HTA SHA-25685767416f8d1e73833ccaa193263d1198857308b3a1185e6f4ebc4164db8584fHTA downloader
HTA SHA-256f1aa14ebfd2da477edba94b34f09f775485688b5958d82fcb072a837e27e246bHTA downloader
HTA SHA-256c477bdfae91e3df9be29e9eeba785467aff294f5250c2eed406765032cb68756HTA downloader
HTA SHA-2566e6bd2f7566ffa52d52fa9d5f048bbb9246d3d50110c6b0c248919ad796c6fd4HTA downloader
HTA SHA-2564540c3af3b1d8c52256f4580dd4d002fadb8c5ff4e32e6a41fdf508455c5b697HTA downloader
HTA SHA-25692a1428e125f33de012c7f52fb0827be3d7e90e38a0e38083181f8c3312adc9cHTA downloader
HTA SHA-256e57409c5e1f8287900c1c3b3e8c099cef537a02949315eb768c88906b0c65addHTA downloader
HTA SHA-2565a76669ec410d0b3e21112a4a6fd3207976b299ee27c5fc3d42f2673170ab95eHTA downloader
HTA SHA-2568092b9de455463296898fcaf8c9955d1c00dae6812c03bba019edf9c059ece33HTA downloader
HTA SHA-25699fcabf7c996d6ec077ccd745a158a3a395403d6a3df9d8da179f3cd5faf81b1HTA downloader
HTA SHA-256875e8d4137e1016b4be869e36e00a9414e89902fd5592a2fb881ebb0e4bd2f8bHTA downloader
HTA SHA-256bd724bbb27f9a71fd44f1c334b003541761071655fa585b64eed3bd78fc28e01HTA downloader
HTA SHA-256a42daeca71a6bdc79fd66b8b6ee413562abf7f72ef093292c86c1e9e7c2be456HTA downloader
HTA SHA-2567e04e86c07213fed7bebccd9953818b102b1b25b78e5f3707e81bad5054cf4e8HTA downloader
HTA SHA-2566547736c31dabb5bef2a290b32a72bf63b5c42dd2a33b5a6520159b41c43b093HTA downloader
HTA SHA-25651503ce1373c7fa72a1da5c5c4b30f88c8224686669ba4b64196591414fdc64cHTA downloader
HTA SHA-2565b3c2442831d4844ea6b86942f1a0ba27170018382cbc362343db63717d0ff02HTA downloader
HTA SHA-25671dea06c2271a46fc2fd6092e2ba0c2f5a2cf5ca8f955ee3375e3ca66a5dc52bHTA downloader
Domain128[.]200[.]178[.]68[.]host[.]secureserver[.]netCampaign infrastructure
Domain13[.]189[.]202[.]64[.]host[.]secureserver[.]netCampaign infrastructure
Domain116[.]181[.]62[.]50[.]host[.]secureserver[.]netCampaign infrastructure
Domain48[.]178[.]169[.]192[.]host[.]secureserver[.]netCampaign infrastructure
Domain115[.]201[.]178[.]68[.]host[.]secureserver[.]netCampaign infrastructure
Domain181[.]202[.]178[.]68[.]host[.]secureserver[.]netCampaign infrastructure
Domain135[.]201[.]178[.]68[.]host[.]secureserver[.]netCampaign infrastructure
Domain85[.]182[.]62[.]50[.]host[.]secureserver[.]netCampaign infrastructure
Domain162[.]201[.]178[.]68[.]host[.]secureserver[.]netCampaign infrastructure
Domain129[.]202[.]178[.]68[.]host[.]secureserver[.]netCampaign infrastructure
Domain76[.]180[.]62[.]50[.]host[.]secureserver[.]netCampaign infrastructure
Domaingexwalltool[.]comCampaign infrastructure
Domainx-wolverine[.]servebbs[.]comCampaign infrastructure
IP address72[.]167[.]48[.]63Campaign infrastructure
IP address209[.]99[.]188[.]28Campaign infrastructure
AutoIt script SHA-256fc820eeb054c781693eca78fed1c418f12b27da2c7c7e73281eb07b25cc7d910AutoIt loader component
AutoIt script SHA-256f76d09cbd455ce18765591b9efa3bde0d31358b6321f7a10fc2e04f65d7407baAutoIt loader component
Casbaneiro payload SHA-2567de637539159dc17ceedb0aae783930ee68639b6d8036ef8147027c5ebca3fc8Casbaneiro payload
Cryptocurrency address0xb4c12078448fdef1f8881a55aab5c81fa194095cEmbedded cryptocurrency address
Cryptocurrency addressbc1q7jt45630rw346729vk5cuatvfyvhfv0330u2p6Embedded cryptocurrency address

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

2 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

12 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

13 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

13 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

13 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

14 hours ago