HomeSecurityCasbaneiro banking trojan cryptocurrency theft & YouTube abuse

Casbaneiro banking trojan cryptocurrency theft & YouTube abuse

ESET, researching the TTPs (tactics, techniques, procedures) of banking trojans in Latin America, discovered the Casbaneiro malware family.

As part of the investigations that led to the discovery of the Amavaldo family, the ESET team also identified Casbaneiro as exhibiting similar functionality – both malware families use the same cryptographic algorithm and distribute a similar email tool.Casbaneiro banking trojan cryptocurrency theft & YouTube abuse

The Casbaneiro family also uses social engineering to trick victims, copying Amavaldo's tactic of using fake pop-ups and forms. These attacks typically focus on convincing the victim to take urgent or necessary actions, such as installing a software update, or verifying credit or bank account information.

Once it infiltrates the victim's device, Casbaneiro uses backdoor commands to take screenshots, restrict access to various banking websites, and record keystrokes.

Additionally, Casbaneiro is used to steal cryptocurrencies through a technique that monitors the clipboard contents for cryptocurrency wallet data. If such data is detected, the malware replaces it with the hacker's cryptocurrency wallet.

The Casbaneiro malware family is characterized by the use of multiple cryptographic algorithms, which are used to hide strings within executable files and to decrypt downloaded payloads and settings. The initial infection vector of Casbaniero is a malicious email – the same method used by Amavaldo.

One of the most interesting aspects of Casbaneiro is the attempts of its operators to hide the domain and port of the C&C server in various places, such as in fake DNS entries, within electronic documents stored in Google Docs, or within fake websites that supposedly belong to legitimate organizations.

In some cases, the C&C server domains have been encrypted and hidden on legitimate websites, most notably in the descriptions of various YouTube videos.
Casbaneiro has primarily targeted banking applications in Brazil and Mexico.
More information about Casbaneiro can be found in the article “Casbaneiro: Dangerous cooking with a secret ingredient” on WeLiveSecurity.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS