FortiGuard Labs observed a Casbaneiro campaign targeting Windows users in Latin America through phishing emails and PDF lures themed as fake invoices and legal notices. The attack used a multi-stage chain with HTA and AutoIt loaders, stealthy environment checks, and selective C2 behavior to steal data and evade analysis. #Casbaneiro #FortiGuardLabs #MicrosoftWindows #MicrosoftOutlook
Keypoints
- Casbaneiro was used in a campaign aimed at users in Latin America, with focus on countries such as Argentina, Peru, Colombia, and Mexico.
- The initial lure relied on phishing emails and PDF documents impersonating invoices and legal notices, often personalized with the recipientâs email address.
- The infection chain used a redirected webpage, a Base64-encoded ZIP download, an HTA downloader, and an AutoIt loader before delivering the final payload.
- The malware performed environment checks such as WMI-based sandbox detection and OS language validation before continuing execution.
- Casbaneiro collected email addresses and Outlook sender/recipient data, then exfiltrated the stolen information to multiple servers.
- The campaign used anti-analysis and stealth tactics, including HTTP 403 responses, infection markers, mutexes, and conditional communication only when victims visited targeted banking websites.
- Fortinet detections included PDF/Phishing.5BB0!tr, JS/Phishing.IBP!tr, and W32/Casbaneiro.EN!tr.spy.
MITRE Techniques
- [T1566.001 ] Phishing: Spearphishing Attachment â Delivered malicious PDFs through phishing emails themed as fake invoices and legal notices (âthe threat actor uses phishing emails and PDFs to prompt victims to click malicious linksâ).
- [T1204.002 ] User Execution: Malicious File â Victims had to open the lure documents and click links to trigger the download chain (âprompt victims to click malicious linksâ).
- [T1105 ] Ingress Tool Transfer â Downloaded the ZIP archive, HTA downloader components, AutoIt interpreter, compiled script, and compressed file from remote locations (âinitiates the download of the archiveâ and âdownloads an AutoIt interpreter, a compiled AutoIt script, and a compressed file separatelyâ).
- [T1027 ] Obfuscated Files or Information â Used Base64-encoded ZIP content and fragmented encrypted strings to hide payloads and configuration (âa Base64-encoded ZIP archive embedded in its JavaScript codeâ and âencrypted strings are split into multiple fragmentsâ).
- [T1057 ] Process Discovery â Checked for target processes to choose injection destination (âThere are two possible injection targets, RegSvcs.exe and mobsync.exeâ).
- [T1055 ] Process Injection â Injected the final payload into a Windows process via the AutoIt loader (âresponsible for injecting the final payload into a Windows processâ).
- [T1518.001 ] Software Discovery: Security Software Discovery â Performed sandbox and environment checks to avoid analysis (âWMI, including sandbox detection and OS language identificationâ).
- [T1082 ] System Information Discovery â Identified OS language and system details to decide whether to continue (âproceeds only if the detected OS language matches one of the languages on the predefined whitelistâ).
- [T1056.001 ] Input Capture: Keylogging â Included keyboard control as part of C2 tasks (âThe C2 tasks include keyboard controlâ).
- [T1115 ] Clipboard Data â Used clipboard injection/pasting to facilitate fraud (âclipboard injectionâ and âclipboard pastingâ).
- [T1047 ] Windows Management Instrumentation â Used WMI queries during environment checks (âthrough Windows Management Instrumentation (WMI)â).
- [T1106 ] Native API â Created mutexes, registry keys, and other Windows artifacts through system-level interactions (âcreates a mutex named GlobolID-4465173{Username}â and âa registry key named after the MD5 hashâ).
- [T1114.001 ] Email Collection â Collected email addresses and Outlook sender/recipient information (âcollects email addresses from the victimâs address book, as well as sender and recipient information from emails stored in Microsoft Outlookâ).
- [T1041 ] Exfiltration Over C2 Channel â Sent stolen data to remote servers (âtransmits the collected data in unencrypted form to a data exfiltration URLâ).
- [T1090 ] Proxy â Used intermediary webpages/redirects and multiple servers to obscure infrastructure relationships (âdistributing stolen data across multiple servers and triggering communications at different timesâ).
- [T1071.001 ] Application Layer Protocol: Web Protocols â Communicated over HTTP with malformed packets and server responses used to mislead analysis (âcaptured the following malformed HTTP packetsâ and âresponds with an HTTP 403 Forbidden statusâ).
- [T1547.001 ] Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder â Established persistence via an LNK file in the Startup folder (âit creates an LNK file in the Startup folderâ).
- [T1112 ] Modify Registry â Created a registry key as an infection marker (âcreates a registry key named after the MD5 hash in HKCUSOFTWAREâ).
Indicators of Compromise
- [File hashes] Malware-related samples and components â 6bb4372d0d02ec87b76409f69d445a93910964f8db457bafafb97a011da59e73, 40d253480f752805e58c21266e40afe99afc96feea0d355732af5bea459db1dd, and 15 more hashes
- [Domains] Hosted infrastructure and delivery sites â gexwalltool[.]com, x-wolverine[.]servebbs[.]com, and 11 more domains
- [IP addresses] Infrastructure and C2-related endpoints â 72[.]167[.]48[.]63, 209[.]99[.]188[.]28, and 10 more IPs
- [Email attachments/content] Phishing lure files â PDF, and 6 email file hashes associated with the lure content
- [File names / path artifacts] Infection markers and persistence artifacts â .Outlook in %APPDATA%, crT-suffixed compressed file, and C:{random name}
- [Cryptocurrency addresses] Embedded wallet addresses in decrypted strings â 0xb4c12078448fdef1f8881a55aab5c81fa194095c, bc1q7jt45630rw346729vk5cuatvfyvhfv0330u2p6