Amavaldo
Amavaldo (canonical ESET naming per August 2019 "From Carnaval to Cinco de Mayo, The journey of Amavaldo" disclosure, FIRST entry in canonical ESET Dirty Dozen Latin American banking trojan series, with subsequent Casbaneiro número dois per ESET October 2019) is a Brazilian-origin banking trojan that was active through November 2020 when it became dormant per ESET December 2021 Dirty Dozen retrospective ("Besides Amavaldo, which became dormant around November 2020, all the other families remain active to this day", operationally significant only ESET Dirty Dozen family that went dormant during series)
Brazilian-origin organized cybercrime attribution via ESET canonical August 2019 first documentation + ESET October 3, 2019 Casbaneiro analysis cluster-defining Amavaldo- related-family identification ("Casbaneiro is closely related to Amavaldo. Both pieces of malware use the same, uncommon cryptographic algorithm in the injector component, they have used a very similar PowerShell script in one of their campaigns and they have been seen distributing a very similar email tool") + ESET January 2021 Vadokrist analysis Amavaldo-family-connection ("Vadokrist shares several important features with families we have described earlier in the series, namely Amavaldo, Casbaneiro, Grandoreiro and Mekotio") + ESET Dirty Dozen canonical December 15, 2021 retrospective with Amavaldo dormancy disclosure + Threatpost canonical October 2020 industry coverage.
standalone malware platform cluster paralleling ousaban + numando + vadokrist in v0.1.142 LATAM banking trojan operators cell expansion (extending v0.1.139 javali + melcoz + mispadu + casbaneiro)
operational target profile Brazil + Mexico primary targets per ESET 2019-2020 tracking + Spanish/Portuguese- speaking countries focus.
operational attack architecture: (1) fake banking pop-up overlay credential capture typical LATAM banking trojan tradecraft + backdoor functionality + screenshots + mouse/keyboard simulation + keystroke capture.
(2) cluster-defining Casbaneiro-related-family signature (same uncommon cryptographic algorithm in injector + similar PowerShell script + similar email tool, curated inversely with v0.1.139 casbaneiro.yaml cluster-cell coherence)
(3) Delphi programming language origin signature typical LATAM banking trojan codebase.
(4) spam distribution typical LATAM banking trojan distribution.
(5) cluster-defining Vadokrist-family-ancestor signature per ESET January 2021 ("Vadokrist shares several important features with families we have described earlier in the series, namely Amavaldo, Casbaneiro, Grandoreiro and Mekotio"), operationally established as ancestral influence on subsequent Vadokrist family.
(6) cluster- defining dormancy since November 2020 per ESET December 2021 retrospective, distinctive operational signature distinguishing Amavaldo from active Mispadu + Casbaneiro + Ousaban + Numando + Vadokrist + Guildma + Grandoreiro + Mekotio that remained active through 2021+ period.
cluster fills the ESET- Dirty-Dozen-FIRST-entry + Casbaneiro-inverse-related- family + Vadokrist-ancestor + dormancy-since-November- 2020 position in Latin American banking trojan operators cell.
canonical illustration of ESET Dirty Dozen series FIRST entry + Casbaneiro-related-family cryptographic lineage + Brazilian-origin LATAM banking trojan dormancy precedent cited in essentially all subsequent Latin American banking trojan industry analyses through 2019-2026 period.