Tuesday, 02 January 2024 12:17 GMT

Casbaneiro Distributes Command Traffic Across Multiple Servers Arabian Post


(MENAFN- The Arabian Post) clearfix">A Casbaneiro banking Trojan campaign targeting users in Latin America is using geofenced phishing, staged malware delivery and separate command-and-control servers to make malicious activity harder to detect and analyse, according to security research published this month.

FortiGuard Labs said it observed the campaign in August, with activity focused on Argentina, Peru, Colombia and Mexico. Victims are approached through phishing emails and PDF documents disguised as invoices, legal notices or purported court-related communications, often incorporating the recipient's email address to make the lure appear more credible.

The infection chain begins when a victim follows a link embedded in the message or PDF. The associated webpage checks the visitor's IP address before delivering malware. Users outside the intended country are redirected to legitimate sites such as Google or YouTube, while targets inside the selected region receive a webpage containing a Base64-encoded ZIP archive embedded in JavaScript.

MENAFN14092026000152002308ID1111663509



The Arabian Post

Legal Disclaimer:
MENAFN provides the information “as is” without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the provider above.



More Story