In August 2026, FortiGuard Labs observed a Casbaneiro attack campaign targeting users in Latin America, using phishing emails and PDF files themed around fake invoices and legal notices as the initial stage.
Casbaneiro exhibits characteristics common to other malware families targeting financial institutions and users in Latin America, including clipboard injection and the use of fake windows to facilitate fraudulent activities. However, their analysis of the recent attack revealed several distinctive network behaviors that differentiate this campaign from previously observed Casbaneiro behavior.
In this attack campaign, the malware is delivered via a multi-stage infection chain that includes an HTA downloader and an AutoIt loader, with the latter responsible for injecting the final payload into a Windows process.
Link to full report: IR-26-254-001_Casbaniero.pdf
Comments