Casbaneiro: A Banking Trojan with Distributed Data-Receiving Servers
Casbaneiro is a banking trojan that steals money and account details from users in Argentina, Colombia, and Mexico. Attackers send fake invoices and legal notices to trick victims into opening infected PDFs and HTA files that load the malware.
- Report priority
- High
- Targets
- Finance+1 more
How it works
- Attackers send fake invoices and legal notices via email to users in Argentina, Colombia, Mexico, and Peru.
- The emails contain malicious PDFs and HTA files that, when opened, download and run AutoIt scripts.
- These scripts check the victim's IP address to confirm they are in a targeted country.
- If the victim visits a banking website, the malware activates, steals email data, hijacks the clipboard, and creates fake windows to trick users into entering their account details.
- The stolen data is split across multiple servers to avoid detection.
What to do
If you live in Argentina, Colombia, Mexico, or Peru and received a suspicious email with a PDF or HTA file claiming to be an invoice or legal notice, check if you opened any unexpected attachments from unknown senders. If you did, monitor your banking activity closely for unauthorized transactions or fake login windows.
Do not open any unexpected attachments from unknown senders. If you suspect you've opened a malicious file, immediately disconnect from the internet, run a full antivirus scan, and contact your bank to report any suspicious activity. Use strong, unique passwords for your banking accounts and enable two-factor authentication if available.
Technical details
Affected software: Finance, Targets: Argentina, Colombia, Mexico
A user in Mexico receives an email claiming to be a legal notice from a government agency. They open the attached PDF, which contains a hidden HTA file. When the user visits their bank's website, the malware activates, steals their email credentials, and replaces legitimate banking windows with fake ones to steal their login details.
Casbaneiro is a banking trojan campaign that emerged in August 2026, primarily targeting users in Argentina, Peru, Colombia, and Mexico. The malware spreads via phishing emails containing fake invoices and legal notices, often delivered as malicious PDFs or HTA downloaders paired with AutoIt loaders. It employs geofencing to restrict infections to specific regions while avoiding systems in Germany, France, and English-speaking environments.
Once active, Casbaneiro steals email credentials, injects fake banking windows to trick victims into entering sensitive data, and monitors clipboard activity for financial details. To evade detection, it uses distributed data-receiving servers, deliberately returns HTTP 403 errors, and activates only when victims visit targeted banking websites. The malware also fragments stolen data across multiple servers and obfuscates communication with malformed HTTP packets.
No CVE ID or CVSS score was assigned.