Casbaneiro banking trojan targets Latin American users via phishing PDFs, using multi-stage infection with AutoIt loader and distributed C2 servers that return HTTP 403 to evade analysis. Casbaneiro banking trojan targets Latin American users through multi-stage infection chain using phishing PDFs, HTA downloader, and AutoIt loader. The malware injects into RegSvcs.exe or mobsync.exe and employs geofencing, language checks, and split component delivery to evade analysis. C2 communication activates only when victims visit targeted bank websites, with data distributed across multiple servers and deliberate HTTP 403 responses to mislead analysts.
Latin America
9 posts
Casbaneiro: A Banking Trojan with Distributed Data-Receiving Servers Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America Unit 42 analyzed two ongoing intrusion campaigns in Latin America (CL-CRI-1131 and CL-CRI-1163) where attackers leveraged commercial LLMs via self-hosted NextChat instances to generate scripts and troubleshoot execution failures. CL-CRI-1131 targeted Mexican transportation and government entities using living-off-the-land techniques, while CL-CRI-1163 targeted the Brazilian financial sector with custom RATs and a Go-based SOCKS5 proxy tool called SockTz. Both campaigns exhibited operational security failures, including exposed staging directories and multi-SAN certificates that revealed their infrastructure and intended targets.
1st June – Threat Intelligence Report This threat intelligence bulletin highlights a surge in data breaches driven by social engineering, alongside the increasing weaponization of AI tools for phishing, malware development, and supply chain attacks. Active exploitation of vulnerabilities in PAN-OS GlobalProtect and Ghost CMS has been observed, while a critical unpatched RCE in Gogs remains a significant risk. Additionally, targeted campaigns like Grandoreiro and JINX-0164 continue to threaten the financial and cryptocurrency sectors using platform-specific malware and DLL side-loading.
Major Cyber Attacks in May 2026: Fake Invitations, Agent Tesla, BlobPhish, and More In May 2026, ANY.RUN observed a surge in sophisticated phishing and malware campaigns utilizing fileless execution, browser-based credential theft, and legitimate workflow abuse. Key threats included Agent Tesla credential harvesting, ClickFix fileless malware, BlobPhish in-memory page generation, and phishing-to-RMM chains bypassing traditional MFA via real-time OTP interception.
LATAM Under Siege: Agent Tesla’s 18-Month Credential Theft Campaign Against Chilean Enterprises An 18-month Agent Tesla campaign is targeting LATAM enterprises, particularly in Chile, using procurement-themed phishing lures. The attack chain employs a multi-stage loader protected by .NET Reactor 6.x, utilizing process hollowing into aspnet_compiler.exe to execute the credential-stealing payload entirely in memory. Stolen data is exfiltrated via cleartext FTP to compromised legitimate infrastructure.
Vibe Hacking: Two AI-Augmented Campaigns Target Government and Financial Sectors in Latin America Trend Micro identified two distinct threat campaigns, SHADOW-AETHER-040 and SHADOW-AETHER-064, leveraging agentic AI to orchestrate attacks against Latin American government and financial institutions. The attackers utilized AI models like Anthropic's Claude to dynamically generate scripts, analyze configurations, and establish SOCKS5 tunnels for lateral movement, demonstrating a shift towards AI-assisted, signature-evasive intrusion operations.
Risk Scenarios for the US’s Strategic Pivot Recorded Future analyzes the cyber and geopolitical risks associated with the US strategic pivot toward the Western Hemisphere. The shift, characterized by increased military intervention against transnational criminal organizations, presents three potential scenarios that elevate risks of state-sponsored espionage, industrialized cybercrime, and the proliferation of commercial spyware and surveillance infrastructure.
Today, trust is the superpower that makes innovation possible This thought leadership article emphasizes the critical role of digital trust and proactive threat intelligence in fostering economic growth. It highlights the partnership between Recorded Future and Mastercard and underscores the need for enhanced public-private collaboration to address rising cyber threats, particularly noting the surge of ransomware incidents in Latin America.
Latin America and the Caribbean Cybercrime Landscape In 2025, the Latin America and the Caribbean (LAC) region faced escalating cybercriminal activity driven by rapid digital adoption and economic instability. Threat actors heavily utilized Telegram and dark web forums to distribute ransomware, banking trojans, and infostealers, increasingly targeting the healthcare, manufacturing, and government sectors while adapting to law enforcement disruptions.