Keypoints
-
<li CyberCartel uses Malware-as-a-Service to deploy banking trojans targeting Chromium-based browsers in LATAM.
<li Malicious Chrome extensions can steal credentials, capture screenshots, cookies, and inject phishing scripts.
<li Web injects enable bypassing two-factor authentication and compromising user accounts.
<li Telegram is used for real-time updates and to communicate with C2 servers, enhancing adaptability.
<li Campaigns focus on financial institutions and government offices in LATAM, with extensive regional activity.
<li A variety of technical components exist, including manifest permissions, content scripts, background scripts, and a Telegram-driven C2 approach.
<li Underground marketplaces offer template builders that lower the barrier to deploying malicious extensions and campaigns.
MITRE Techniques
- [T1566.001] Phishing β Spearphishing Link β The Victim unknowingly visits a phishing website and downloads a file. βThe Victim unknowingly visits a phishing website and downloads a fileβ
- [T1056] Input Capture (Web Injects) β Web injects and Man-in-the-Browser activities to manipulate web sessions and steal credentials. βWeb injects are back on the rise. They are powerful malicious tools integrated with multiple banking trojans that permit a threat actor to bypass two-factor authentication (2FA) and compromise a userβs bank account.β
- [T1071.001] Web Protocols β C2 communications over Web protocols (Telegram for updates and data transmission). βTo ensure its persistence, the malware employs a flexible command and control (C2) system and adaptive configuration, often communicated via a Telegram channel.β
- [T1041] Exfiltration Over C2 Channel β Stolen data is transmitted to a C2 server. βThe stolen information is sent to a Command and Control (C&C) serverβ
Indicators of Compromise
- [URL] context β https://facturacionmexico.net/ok.js, https://dlxfreights.site/mx/sbi/main.js, and other related domains
- [URL] context β https://css.imagesccs.com/jquery.js, https://www.cssangular.com/jquery.js, https://www.angularcss.com/jquery.js
Read more: https://securityintelligence.com/posts/unveiling-latest-banking-trojan-threats-latam