Casbaneiro, also known as Metamorfo, is a Windows banking trojan targeting online-banking users in Latin America. Historical infections were concentrated in Brazil, while an August 2026 campaign targeted Argentina, Peru, Colombia, and Mexico. Its principal functions are stealing banking credentials and personal information and enabling operator-controlled financial fraud. It monitors banking applications and browser window titles, captures screenshots and keystrokes, and displays deceptive bank notifications or windows to solicit sensitive information. Some variants disable browser autocomplete to force manual password entry. Remote commands support keyboard control, clipboard pasting, file execution, and command execution.
Distribution includes phishing emails with malicious HTML attachments and invoice- or legal-notice-themed PDF lures. The August 2026 campaign used geographically filtered landing pages, an HTML Application downloader, and separately downloaded AutoIt components to load and inject the final payload into legitimate Windows processes. Historical campaigns used deceptive Windows Installer packages containing legitimate, digitally signed executables alongside malicious DLLs. Casbaneiro abuses DLL side-loading and process injection to execute within trusted processes, including Windows Media Player. Persistence mechanisms include startup scripts or shortcuts and scheduled tasks.
Casbaneiro performs process and application discovery, collects host information, and applies locale or language checks to restrict execution. Evasion measures include hidden windows, fragmented runtime string decryption, componentized delivery, and anti-analysis checks. In the August 2026 campaign, it collected address-book entries and Microsoft Outlook sender and recipient metadata, transmitting that information without encryption to separate servers. Its primary banking command channel activated only after a victim visited a targeted banking website. Communication mechanisms vary across versions and include raw TCP and encrypted HTTPS; the 2026 campaign also used malformed HTTP requests and expected HTTP 403 responses as part of its communication workflow.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Several behaviors in this sample are similar to those observed in the Casbaneiro (Metamorfo) banking malware lineage.
The point of all this is to drop Casbaneiro, a classic banking Trojan that triggers when victims visit their cryptocurrency or financial service providers online.
46 distinct techniques documented for this family, organized by ATT&CK tactic.
Adversaries may use a non-application layer protocol for communication between host and C2 server or among infected hosts within a network. Specific examples include use of network layer protocols, such as the Internet Control Message Protocol (ICMP), transport layer protocols, such as the User Datagram Protocol (UDP), session layer protocols, such as Socket Secure (SOCKS), as well as redirected/tunneled protocols, such as Serial over LAN (SOL).
130 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
151 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Windows-focused banking Trojan delivered through personalized phishing PDFs, Base64-encoded ZIP archives, HTA downloaders, and AutoIt-based staged loaders. It performs anti-analysis and regional filtering, persists via a Startup shortcut, injects into RegSvcs.exe or mobsync.exe, collects address-book and Outlook email metadata, and waits for visits to targeted bank sites before contacting its command infrastructure. It supports keyboard control, clipboard pasting, file execution, command execution, and bank-targeted fake-window functions. Its communications include malformed HTTP requests and an expected HTTP 403 response used as part of its data-exfiltration workflow.
Windows-focused banking Trojan distributed through phishing PDF lures and staged HTA/AutoIt downloads. It uses regional filtering and anti-analysis checks, injects into RegSvcs.exe or mobsync.exe, establishes Startup-folder persistence, harvests address-book and Outlook email metadata, and activates its principal command channel when a victim visits a targeted banking website. It supports keyboard control, clipboard pasting, command/file execution, and fake banking windows to facilitate fraud.
A banking trojan delivered through phishing emails using a multi-stage HTA downloader and AutoIt loader. It injects its payload into a Windows process and supports financial fraud through clipboard injection and fake windows; it uses distributed data-receiving servers for network communications.
Windows-focused Latin American banking trojan delivered through phishing PDFs, an HTA downloader, and an AutoIt loader. It injects its payload into RegSvcs.exe or mobsync.exe, establishes Startup-folder persistence, targets bank-site activity before initiating C2, uses clipboard injection and fraudulent windows, and steals Outlook address-book and email sender/recipient data for unencrypted exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.