Summary
FortiGuard Labs has published analysis of an August 2026 Casbaneiro banking trojan campaign targeting online banking users in Argentina, Peru, Colombia, and Mexico. The campaign uses phishing emails themed as urgent invoices and legal notices with personalized PDF lures, a geofenced delivery chain that filters victims by IP address, and a multi-stage infection process that injects into legitimate Windows processes and remains dormant until the victim opens a targeted bank website. A secondary module called Horabot harvests the victim’s email contacts and propagates new phishing campaigns to each one, giving the campaign worm-like self-replication characteristics. Stolen data is exfiltrated across distributed command-and-control servers using deliberately malformed HTTP requests designed to complicate network-based detection.
Timeline
| Date | Event |
|---|---|
| August 2026 | FortiGuard Labs observes active Casbaneiro campaign targeting Latin American banking users |
| Sep 14, 2026 | FortiGuard Labs publishes full technical analysis including indicators of compromise |
What Happened
The attack begins with a phishing email carrying urgency-driven themes — an unpaid invoice, a legal proceeding, a court summons — addressed to the victim by name or email address. The embedded link first checks the visitor’s IP address: visitors outside Argentina, Peru, Colombia, and Mexico are redirected to benign sites, while targets in the selected countries are served a page that silently downloads a Base64-encoded ZIP archive.
The archive contains an HTA downloader that retrieves external JavaScript and an XML-based script package. Windows Management Instrumentation inspects the victim environment for sandbox indicators and operating system language settings; machines detected as analysis environments or running German, French, or English system languages abort the infection chain. On passing, the loader downloads a legitimate AutoIt interpreter, a compiled script, and a compressed payload component separately. A fake Windows service dialog is displayed during installation to explain unexpected activity to the victim.
Once installed, Casbaneiro injects into RegSvcs.exe or mobsync.exe and remains dormant. The activation trigger is the victim opening any website matching a list of targeted Latin American banks and financial platforms. On activation, Casbaneiro contacts its command infrastructure, overlays fake login windows on legitimate banking pages to intercept credentials, logs keystrokes, and performs clipboard injection to substitute attacker-controlled cryptocurrency addresses for any copied payment addresses.
Stolen data is split across multiple servers and exfiltrated using deliberately malformed HTTP requests to complicate network traffic analysis. The Horabot module accesses the victim’s email account, extracts contacts, and sends new phishing emails carrying a modified version of the original lure to each contact — enabling geometric propagation from each successful infection.
Note on Domain Intelligence
Casbaneiro is a malware campaign targeting individual banking users across multiple Latin American financial institutions. No single institution or vendor domain is the subject of this bulletin. Domain intelligence for specific targeted financial institutions is available at warmbadge.com where those domains have been evaluated.
The Trust Observatory · thetrustobservatory.com · September 14, 2026
The Trust Observatory · thetrustobservatory.com · September 8, 2026