Executive Summary
In August 2026, a new Casbaneiro campaign was identified targeting financial institutions and users in Latin America, specifically Argentina, Peru, Colombia, and Mexico. The attack utilizes a highly selective infection chain that employs geofencing at the delivery stage and environment checks (OS language and sandbox detection) to ensure it only executes on intended targets. The malware shares significant code similarities with the Ousaban family, specifically its string decryption algorithms.
The campaign is technically notable for its evasion techniques, including the use of distributed data-receiving servers where one server deliberately returns HTTP 403 Forbidden responses to mislead analysts. Casbaneiro remains dormant until a victim visits a targeted banking website, at which point it initiates C2 communication, performs clipboard injection for cryptocurrency theft, and deploys fake windows to capture credentials. The use of malformed HTTP packets further complicates traditional network inspection.
This threat poses a high risk to the financial services sector in the LATAM region. The sophistication of its multi-stage loader and selective activation mechanism suggests a mature adversary focused on long-term persistence and avoiding automated detection sandboxes.
