FraudHIGH

Casbaneiro Phishing Targets Latin America and Europe

Featured image for Casbaneiro Phishing Targets Latin America and Europe
THThe Hacker News
📰 2 sources·Summary by CyberPings Editorial·AI-assisted·Reviewed by Rohit Rana
Updated:
🎯

Basically, hackers are tricking people into opening fake court documents to steal their banking info.

Quick Summary

A new phishing campaign is targeting Spanish-speaking users in Latin America and Europe, delivering banking trojans via dynamic PDFs. This sophisticated attack employs social engineering tactics to compromise victims. Users should remain vigilant and take precautions against such threats.

What Happened

A multi-pronged phishing campaign has emerged, targeting Spanish-speaking users in organizations across Latin America and Europe. This campaign aims to deliver Windows banking trojans, specifically Casbaneiro (also known as Metamorfo), through another malware called Horabot. The Brazilian cybercrime group behind this operation is tracked under the aliases Augmented Marauder and Water Saci. They have been active since at least October 2025, employing various tactics to compromise users.

The attack begins with a phishing email that uses court summons-themed messages to lure victims into opening a password-protected PDF attachment. Once the PDF is opened, it contains a link that directs users to a malicious site, triggering the download of a ZIP archive. This archive executes interim HTML Application (HTA) and VBS payloads designed to check the victim's environment for security software and download further malicious components.

Who's Being Targeted

The primary targets of this campaign are Spanish-speaking users across various organizations in Latin America and Europe. The attackers leverage WhatsApp and email as their primary delivery mechanisms. By using script-based WhatsApp automation, they can effectively compromise retail and consumer users while also targeting enterprise environments through sophisticated email hijacking techniques.

This dual approach allows the attackers to maximize their reach and effectiveness. The use of dynamic PDF generation and ClickFix social engineering tactics demonstrates their adaptability and innovation in bypassing modern security measures.

Signs of Infection

Victims may notice several signs indicating a potential infection. These include receiving unexpected emails with court summons attachments, unusual activity in their email accounts, or the presence of unknown files on their systems. The VBS script used in this campaign performs checks for antivirus software, which can indicate a more sophisticated threat.

Additionally, the malware can propagate itself by sending phishing emails from compromised accounts, making it harder for victims to recognize the threat. Users should be vigilant about any suspicious emails or attachments, especially those that seem to come from trusted contacts.

How to Protect Yourself

To safeguard against this phishing campaign, users should take several proactive measures:

  • Do not open unexpected email attachments, especially those that are password-protected.
  • Verify the sender's email address before clicking on any links or downloading files.
  • Use updated antivirus software to help detect and block malware.
  • Educate yourself and your team about phishing tactics and how to recognize suspicious communications.

By implementing these strategies, individuals and organizations can significantly reduce their risk of falling victim to this evolving threat landscape. The integration of multiple attack vectors by the Augmented Marauder group highlights the importance of staying informed and vigilant in cybersecurity practices.

🔒 Pro insight: The use of dynamic PDF generation and WhatsApp automation indicates a significant evolution in phishing tactics, making detection increasingly challenging.

Original article from

THThe Hacker News
Read Full Article

Also covered by

SCSC Media

Phishing campaign delivers Casbaneiro and Horabot banking trojans

Read Article
DADark Reading

Bank Trojan 'Casbaneiro' Worms Through Latin America

Read Article

Related Pings

HIGHFraud

Drift Hack - $285 Million Theft Linked to DPRK Operation

A major hack on Drift resulted in a staggering $285 million theft, linked to a six-month DPRK social engineering operation. This highlights the growing threat of state-sponsored cybercrime in the cryptocurrency sector. Organizations must enhance their security measures to prevent similar attacks.

The Hacker News·
HIGHFraud

Device Code Phishing - Attacks Surge 37 Times in 2026

Device code phishing attacks have skyrocketed this year, with a 37x increase. Users of IoT and streaming devices are particularly at risk. New phishing kits like EvilTokens are making these attacks easier for cybercriminals. Stay alert and protect your accounts.

BleepingComputer·
HIGHFraud

Job Scams - Coca-Cola and Ferrari Offers Are Traps

Scammers are impersonating Coca-Cola and Ferrari with fake job offers to steal your passwords. Job seekers are at high risk as these scams become more sophisticated. Protect your personal information by verifying job offers directly with companies.

Malwarebytes Labs·
HIGHFraud

FCC Proposes $4.5 Million Fine for Voxbeam's Fraudulent Calls

The FCC is proposing a hefty fine against Voxbeam for allowing fraudulent calls to reach American consumers. This could lead to stricter regulations on voice service providers. Stay alert to protect your personal information from scams.

The Record·
HIGHFraud

Windows Extortion Plot - Engineer Pleads Guilty to Charges

A former engineer has pleaded guilty to locking Windows admins out of servers in an extortion scheme. This incident underscores the risks of insider threats. Rhyne's actions could lead to a 15-year prison sentence. Companies must strengthen their cybersecurity measures to prevent similar attacks.

BleepingComputer·
MEDIUMFraud

Business Email Compromise - The New Threat Landscape Explained

A recent fraud attempt shows how business email compromise is evolving. Small organizations are now prime targets for these scams. Awareness is key to staying safe.

Cisco Talos Intelligence·