Casbaneiro: A Banking Trojan with Distributed Data-Receiving Servers

Casbaneiro: A Banking Trojan with Distributed Data-Receiving Servers
FortiGuard Labs observed a Casbaneiro campaign targeting Windows users in Latin America through phishing emails and PDF lures themed as fake invoices and legal notices. The attack used a multi-stage chain with HTA and AutoIt loaders, stealthy environment checks, and selective C2 behavior to steal data and evade analysis. #Casbaneiro #FortiGuardLabs #MicrosoftWindows #MicrosoftOutlook

Keypoints

  • Casbaneiro was used in a campaign aimed at users in Latin America, with focus on countries such as Argentina, Peru, Colombia, and Mexico.
  • The initial lure relied on phishing emails and PDF documents impersonating invoices and legal notices, often personalized with the recipient’s email address.
  • The infection chain used a redirected webpage, a Base64-encoded ZIP download, an HTA downloader, and an AutoIt loader before delivering the final payload.
  • The malware performed environment checks such as WMI-based sandbox detection and OS language validation before continuing execution.
  • Casbaneiro collected email addresses and Outlook sender/recipient data, then exfiltrated the stolen information to multiple servers.
  • The campaign used anti-analysis and stealth tactics, including HTTP 403 responses, infection markers, mutexes, and conditional communication only when victims visited targeted banking websites.
  • Fortinet detections included PDF/Phishing.5BB0!tr, JS/Phishing.IBP!tr, and W32/Casbaneiro.EN!tr.spy.

MITRE Techniques

  • [T1566.001 ] Phishing: Spearphishing Attachment – Delivered malicious PDFs through phishing emails themed as fake invoices and legal notices (‘the threat actor uses phishing emails and PDFs to prompt victims to click malicious links’).
  • [T1204.002 ] User Execution: Malicious File – Victims had to open the lure documents and click links to trigger the download chain (‘prompt victims to click malicious links’).
  • [T1105 ] Ingress Tool Transfer – Downloaded the ZIP archive, HTA downloader components, AutoIt interpreter, compiled script, and compressed file from remote locations (‘initiates the download of the archive’ and ‘downloads an AutoIt interpreter, a compiled AutoIt script, and a compressed file separately’).
  • [T1027 ] Obfuscated Files or Information – Used Base64-encoded ZIP content and fragmented encrypted strings to hide payloads and configuration (‘a Base64-encoded ZIP archive embedded in its JavaScript code’ and ‘encrypted strings are split into multiple fragments’).
  • [T1057 ] Process Discovery – Checked for target processes to choose injection destination (‘There are two possible injection targets, RegSvcs.exe and mobsync.exe’).
  • [T1055 ] Process Injection – Injected the final payload into a Windows process via the AutoIt loader (‘responsible for injecting the final payload into a Windows process’).
  • [T1518.001 ] Software Discovery: Security Software Discovery – Performed sandbox and environment checks to avoid analysis (‘WMI, including sandbox detection and OS language identification’).
  • [T1082 ] System Information Discovery – Identified OS language and system details to decide whether to continue (‘proceeds only if the detected OS language matches one of the languages on the predefined whitelist’).
  • [T1056.001 ] Input Capture: Keylogging – Included keyboard control as part of C2 tasks (‘The C2 tasks include keyboard control’).
  • [T1115 ] Clipboard Data – Used clipboard injection/pasting to facilitate fraud (‘clipboard injection’ and ‘clipboard pasting’).
  • [T1047 ] Windows Management Instrumentation – Used WMI queries during environment checks (‘through Windows Management Instrumentation (WMI)’).
  • [T1106 ] Native API – Created mutexes, registry keys, and other Windows artifacts through system-level interactions (‘creates a mutex named GlobolID-4465173{Username}’ and ‘a registry key named after the MD5 hash’).
  • [T1114.001 ] Email Collection – Collected email addresses and Outlook sender/recipient information (‘collects email addresses from the victim’s address book, as well as sender and recipient information from emails stored in Microsoft Outlook’).
  • [T1041 ] Exfiltration Over C2 Channel – Sent stolen data to remote servers (‘transmits the collected data in unencrypted form to a data exfiltration URL’).
  • [T1090 ] Proxy – Used intermediary webpages/redirects and multiple servers to obscure infrastructure relationships (‘distributing stolen data across multiple servers and triggering communications at different times’).
  • [T1071.001 ] Application Layer Protocol: Web Protocols – Communicated over HTTP with malformed packets and server responses used to mislead analysis (‘captured the following malformed HTTP packets’ and ‘responds with an HTTP 403 Forbidden status’).
  • [T1547.001 ] Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder – Established persistence via an LNK file in the Startup folder (‘it creates an LNK file in the Startup folder’).
  • [T1112 ] Modify Registry – Created a registry key as an infection marker (‘creates a registry key named after the MD5 hash in HKCUSOFTWARE’).

Indicators of Compromise

  • [File hashes] Malware-related samples and components – 6bb4372d0d02ec87b76409f69d445a93910964f8db457bafafb97a011da59e73, 40d253480f752805e58c21266e40afe99afc96feea0d355732af5bea459db1dd, and 15 more hashes
  • [Domains] Hosted infrastructure and delivery sites – gexwalltool[.]com, x-wolverine[.]servebbs[.]com, and 11 more domains
  • [IP addresses] Infrastructure and C2-related endpoints – 72[.]167[.]48[.]63, 209[.]99[.]188[.]28, and 10 more IPs
  • [Email attachments/content] Phishing lure files – PDF, and 6 email file hashes associated with the lure content
  • [File names / path artifacts] Infection markers and persistence artifacts – .Outlook in %APPDATA%, crT-suffixed compressed file, and C:{random name}
  • [Cryptocurrency addresses] Embedded wallet addresses in decrypted strings – 0xb4c12078448fdef1f8881a55aab5c81fa194095c, bc1q7jt45630rw346729vk5cuatvfyvhfv0330u2p6


Read more: https://feeds.fortinet.com/~/968920310/0/fortinet/blog/threat-research~Casbaneiro-A-Banking-Trojan-with-Distributed-DataReceiving-Servers