Casbaneiro Distributes Command Traffic Across Multiple Servers Arabian Post
FortiGuard Labs said it observed the campaign in August, with activity focused on Argentina, Peru, Colombia and Mexico. Victims are approached through phishing emails and PDF documents disguised as invoices, legal notices or purported court-related communications, often incorporating the recipient's email address to make the lure appear more credible.
The infection chain begins when a victim follows a link embedded in the message or PDF. The associated webpage checks the visitor's IP address before delivering malware. Users outside the intended country are redirected to legitimate sites such as Google or YouTube, while targets inside the selected region receive a webpage containing a Base64-encoded ZIP archive embedded in JavaScript.
Legal Disclaimer:
MENAFN provides the
information “as is” without warranty of any kind. We do not accept any
responsibility or liability for the accuracy, content, images, videos,
licenses, completeness, legality, or reliability of the information
contained in this article. If you have any complaints or copyright issues
related to this article, kindly contact the provider above.

Comments
No comment