Casbaneiro Campaign Targeting Latin American Banking Sector
Score: 8/10

Casbaneiro Campaign Targeting Latin American Banking Sector

Casbaneiro banking trojan targets Latin American users via geofenced phishing and a multi-stage AutoIt infection chain to exfiltrate financial credentials.

Executive Summary

In August 2026, a new Casbaneiro campaign was identified targeting financial institutions and users in Latin America, specifically Argentina, Peru, Colombia, and Mexico. The attack utilizes a highly selective infection chain that employs geofencing at the delivery stage and environment checks (OS language and sandbox detection) to ensure it only executes on intended targets. The malware shares significant code similarities with the Ousaban family, specifically its string decryption algorithms.

The campaign is technically notable for its evasion techniques, including the use of distributed data-receiving servers where one server deliberately returns HTTP 403 Forbidden responses to mislead analysts. Casbaneiro remains dormant until a victim visits a targeted banking website, at which point it initiates C2 communication, performs clipboard injection for cryptocurrency theft, and deploys fake windows to capture credentials. The use of malformed HTTP packets further complicates traditional network inspection.

This threat poses a high risk to the financial services sector in the LATAM region. The sophistication of its multi-stage loader and selective activation mechanism suggests a mature adversary focused on long-term persistence and avoiding automated detection sandboxes.

Key Details

Threat Name

Casbaneiro

Affects

—

Adversary

Casbaneiro Other Adversaries and Aliases: Ousaban

Malware/Tools

Casbaneiro, Ousaban

Report Score

8out of 10
Quality Score
Good
IOC Quality8
TTP Details9
Detection Guidance6
Enterprise Relevance8
Clarity & Structure9
Technical Depth8

Sources