Brazilian hackers appear to have been targeting thirty Portuguese government and private financial institutions since 2021 as part of a campaign called “Operation Magalenha.”

Among the targets are: ActivoBank, Caixa Geral de Depósitos, CaixaBank, Citibanamex, Santander, Millennium BCP, ING, Banco BPI and Novobanco.
The campaign was revealed by a report from Sentinel Labs that explained the attacks, detailing the tools used by the hackers, the various infection vectors, and the malware.
See also: Armenia: Journalists and activists targeted by Pegasus spyware
Analysts were able to gather information about the origin and tactics of the attackers thanks to a server misconfiguration that exposed files, directories, internal mail, and more.
How does the infection start?
Attackers use many methods to distribute their malware. For example, phishing emails pretending to come from Energias de Portugal (EDP) and the Portuguese Tax and Customs Authority (AT) have been detected. They also use social engineering and malicious websites that mimic these organizations.
In all cases, the infection begins with the execution of an obfuscated VB script that retrieves and executes a malware loader, which in turn loads two variants of the “PeepingTitle” backdoor onto the victim’s system.
“VB scripts are obfuscated so that the malicious code is scattered in large amounts of code comments, which are usually pasted content from publicly available code repositories,” Sentinel Labs explains in the report.
“This is a simple, yet effective technique for avoiding detection – the scripts available on VirusTotal have relatively low detection rates.“.
See also: Volt Typhoon: Chinese hackers breach critical US infrastructure
Analysts explain that the purpose of these scripts is to distract users while downloading malware and steal EDP and AT credentials by directing them to fake portals.

Backdoor “PeepingTitle”
PeepingTitle is malware written in Delphi, which Sentinel Labs believes was developed by an individual or group.
According to BleepingComputer, the reason attackers use two variants of the malware is to use one to record the victim's screen and the second to monitor windows and user with them. Also, the second variant can carry additional payloads.
The malware checks for windows that match a list of financial institutions and, when it finds one, it records all user data (including credentials) and sends it to the Brazilian hackers.
The PeepingTitle backdoor can also capture screenshots, terminate processes, change the monitoring interval configuration, and use payloads from executable files or DLL files, using Windows rundll32.
See also: WordPress: Hackers target 1.5 million websites
Sentinel Labs has observed several instances where Brazilian hackers demonstrated the ability to overcome operational obstacles during “Operation Magalenha.” In mid-2022, the group stopped abusing DigitalOcean Spaces for C2 and malware hosting and distribution and began using more “dark” cloud service providers , such as Russia-based Timeweb
Cyberattacks threat that individuals should take seriously. By being vigilant, using strong passwords, enabling two-factor authentication, avoiding phishing scams, securing devices, and using a VPN, you can significantly reduce the risk of your financial information being compromised. However, it is also the responsibility of banks and financial institutions to invest in strong cybersecurity measures and educate their customers about the risks of cybercrime.
Source: www.bleepingcomputer.com
