Home/Threat Actor/Casbaneiro / Metamorfo
Threat Actor

Casbaneiro / Metamorfo

casbaneiro · latin_america_brazilian_organized_cybercrime · active since 2018-04

Casbaneiro (canonical ESET naming per October 3, 2019 "Dangerous cooking with a secret ingredient" disclosure, número dois in ESET Dirty Dozen Latin American banking trojan series) / Metamorfo (alternative BitDefender + MITRE ATT&CK S0455 naming) / Ponteiro (Fortinet alternative naming) is a Brazilian-origin Latin American banking trojan active since at least April 2018 per MITRE ATT&CK S0455 attribution + BitDefender mid-2018 tracking; Brazilian-origin organized cybercrime attribution via ESET canonical October 2019 first documentation ("Casbaneiro, also known as Metamorfo, is a typical Latin American banking trojan that targets banks and cryptocurrency services in Brazil and Mexico") + MITRE ATT&CK S0455 canonical attribution ("Metamorfo is a Latin-American banking trojan operated by a Brazilian cybercrime group that has been active since at least April 2018") + BitDefender April 3, 2020 canonical disclosure (C. Erlich "The Avast Abuser: Metamorfo Banking" per Malpedia: "Metamorfo is a family of banker Trojans that has been active since mid-2018. It primarily targets Brazilians and is delivered mostly through Office files rigged with macros in spam attachments") + ESET Dirty Dozen canonical December 15, 2021 retrospective with Casbaneiro Brazil dominance per telemetry ("Ousaban and Casbaneiro dominated Brazil in the latest months") + Trend Micro October 2025 Augmented Marauder / Water Saci first documentation + BlueVoyant April 2026 canonical Horabot + WhatsApp Web + ClickFix disclosure (Thomas Elkins + Joshua Green via The Hacker News)

standalone malware platform cluster paralleling javali + melcoz + mispadu in v0.1.139 LATAM banking trojan operators cell expansion.

operational target profile Brazil + Mexico (primary historical targets) + 2025-2026 expansion to Spanish-speaking Latin America + Europe per BlueVoyant.

operational attack architecture: (1) Office files with macros in spam attachments primary distribution per BitDefender.

(2) fake banking pop-up overlay credential capture typical LATAM banking trojan tradecraft + screen capture + mouse/keyboard simulation + keystroke capture.

(3) cluster-defining AES-256 + SynCrypto Delphi library + SHA-256 password-derived key encryption per ESET ("Commands received from the C&C server are encrypted using AES-256. The SynCrypto Delphi library is used. The AES key is derived via SHA-256 from a password stored in the binary")

(4) Bitcoin wallet clipboard replacement hijack cluster-cell coherent with Melcoz + Grandoreiro + Mispadu crypto theft tradecraft.

(5) cluster-defining C2 hiding via remotely stored documents + legitimate + fake websites + fake DNS entries per ESET.

(6) cluster-defining Amavaldo-related family signature per ESET ("Casbaneiro is closely related to Amavaldo. Both pieces of malware use the same, uncommon cryptographic algorithm in the injector component, they have used a very similar PowerShell script in one of their campaigns and they have been seen distributing a very similar email tool")

(7) Re- Loader cracking tool legitimate-install masquerade per ESET.

(8) Delphi programming language origin signature.

2025-2026 evolution tradecraft (cluster- defining newer capabilities): (9) Horabot propagation mechanism per BlueVoyant April 2026 ("Casbaneiro's Delphi DLL module contacts a command-and-control C2 server to fetch a PowerShell script that employs Horabot to distribute the malware via phishing emails to harvested contacts from Microsoft Outlook")

(10) WhatsApp Web distribution vector per BlueVoyant ("Water Saci has a history of using WhatsApp Web as a distribution vector for disseminating banking trojans like Maverick and Casbaneiro in a worm-like manner"); (11) ClickFix social engineering per Kaspersky ("recent campaigns highlighted by Kaspersky have leveraged the ClickFix social engineering tactic to dupe users into running malicious HTA files with the end goal of deploying Casbaneiro and the Horabot spreader")

(12) dynamic PDF generation impersonating Spanish judicial summons signature per BlueVoyant April 2026 ("Rather than distributing a static file or hardcoded link as seen in older Horabot campaigns, this script initiates an HTTP POST request to a remote PHP API... The server dynamically forges a bespoke, password-protected PDF impersonating a Spanish judicial summons, which is returned to the infected host")

cluster fills the Amavaldo-related-family + AES-256-SynCrypto-encryption + cryptocurrency-service-targeting + WhatsApp-Web- Horabot-ClickFix-2025-2026-evolution position in Latin American banking trojan operators cell; canonical illustration of ESET Dirty Dozen LATAM banking trojan + AES-256 SynCrypto encryption + Amavaldo-related-family cryptographic lineage + C2 hiding via legitimate services + 2025-2026 Horabot/ WhatsApp/ClickFix evolution cited in essentially all subsequent Latin American banking trojan industry analyses through 2018-2026 period.

latin_america_brazilian_organized_cybercrime confidence: high 18 aliases
Sigma rules200 YARA rules0 Live IOCs0 CVEs exploited0

Profile

Casbaneiro (canonical ESET naming per October 3, 2019 "Dangerous cooking with a secret ingredient" disclosure) / Metamorfo (alternative BitDefender + MITRE ATT&CK S0455 naming) / Ponteiro (Fortinet alternative naming) is a Brazilian-origin Latin American banking trojan active since at least April 2018 per MITRE ATT&CK + BitDefender mid-2018 tracking. Brazilian-origin organized cybercrime attribution via ESET canonical October 2019 first documentation + MITRE ATT&CK S0455 canonical attribution + BitDefender April 2020 canonical disclosure + ESET Dirty Dozen canonical December 2021 retrospective + Trend Micro October 2025 Augmented Marauder / Water Saci attribution + BlueVoyant April 2026 Horabot + WhatsApp + ClickFix disclosure. Standalone malware platform cluster paralleling javali + melcoz + mispadu in v0.1.139 LATAM banking trojan operators cell expansion.

Operational target profile
  • Brazil + Mexico primary targets per ESET + MITRE ATT&CK S0455.
  • Banks + cryptocurrency services per ESET.
  • 2021 Brazil dominance per ESET telemetry.
  • 2025-2026 expansion to Spanish-speaking Latin America + Europe per BlueVoyant April 2026 Operational attack architecture: (1) Office files with macros in spam attachments (signature): per BitDefender April 2020, primary distribution method (2) Fake banking pop-up overlay credential capture (cluster-defining): typical LATAM banking trojan tradecraft via social engineering pop-up windows (3) AES-256 + SynCrypto Delphi library + SHA-256 password-derived key encryption (cluster-defining): per ESET, distinctive encryption tradecraft (4) Bitcoin wallet clipboard replacement hijack (signature): per ESET, cryptocurrency theft tradecraft cluster-cell coherent with Melcoz + Grandoreiro + Mispadu (5) C2 hiding via remotely stored documents + legitimate + fake websites + fake DNS entries (cluster-defining): per ESET, distinctive C2 concealment tradecraft (6) Amavaldo-related family signature (cluster- defining): per ESET, "same, uncommon cryptographic algorithm in the injector component" + "very similar PowerShell script" + "very similar email tool" (7) Re-Loader cracking tool legitimate-install masquerade (signature): per ESET, install with expected legitimate software for less suspicion (8) Delphi programming language origin (signature) 2025-2026 evolution tradecraft (cluster-defining newer capabilities): (9) Horabot propagation mechanism (cluster-defining 2025-2026): per BlueVoyant April 2026, Horabot PowerShell spreader for Casbaneiro distribution via phishing emails to harvested Outlook contacts (10) WhatsApp Web distribution vector (cluster- defining 2025-2026): per BlueVoyant, Augmented Marauder / Water Saci uses WhatsApp Web as distribution vector for Maverick + Casbaneiro (11) ClickFix social engineering (cluster-defining 2025-2026): per Kaspersky, ClickFix dupes users into running malicious HTA files for Casbaneiro + Horabot deployment (12) Dynamic PDF generation impersonating Spanish judicial summons (signature 2026): per BlueVoyant April 2026, bespoke password-protected PDFs The cluster fills the Amavaldo-related-family + AES- 256-SynCrypto-encryption + cryptocurrency-service- targeting + WhatsApp-Web-Horabot-ClickFix-2025-2026- evolution position in the Latin American banking trojan operators cell.

Aliases

18
casbaneirometamorfometamorphoponteirocasbaneiro metamorfocasbaneiro_metamorfocasbaneiro_banking_trojancasbaneiro_malwareaugmented marauderwater saciaugmented_marauderwater_sacicasbaneiro metamorfo brazilian banking trojancasbaneiro eset dirty dozen latin americacasbaneiro mitre attack s0455 metamorfocasbaneiro amavaldo related familycasbaneiro brazil mexico cryptocurrency targetingcasbaneiro horabot whatsapp clickfix

Notable Campaigns

10
2026BlueVoyant April 2026 Canonical Horabot + WhatsApp + ClickFix Disclosure
2025Trend Micro October 2025, Augmented Marauder / Water Saci First Documentation
2021ESET Dirty Dozen Canonical Retrospective, Casbaneiro Brazil Dominance (December 15, 2021)
2020BitDefender April 2020 Canonical Metamorfo Disclosure (C. Erlich)
2019-2020Casbaneiro AES-256 SynCrypto Encryption Signature
2019-2020Casbaneiro C2 Hiding Signature
2019ESET Canonical First Disclosure (October 3, 2019)
2019Casbaneiro = Amavaldo Related Family Signature (2019)
2018-2026Continued Industry Reference Status (2018-2026)
2018Casbaneiro Origin, Active Since April 2018 per MITRE ATT&CK

Attribution & Reporting

Key reporting
reportESET WeLiveSecurity: Casbaneiro, Dangerous cooking with a secret ingredient (October 3, 2019), canonical first documentation número dois in ESET Dirty Dozen series
reportESET WeLiveSecurity: The Dirty Dozen of Latin America, From Amavaldo to Zumanek (December 15, 2021), canonical retrospective with Casbaneiro Brazil dominance
reportMITRE ATT&CK Software S0455 Metamorfo: canonical Brazilian cybercrime group April 2018+ attribution
reportBitDefender (C. Erlich): The Avast Abuser, Metamorfo Banking analysis (April 3, 2020), canonical Metamorfo disclosure
reportTrend Micro October 2025: canonical Augmented Marauder / Water Saci Brazilian cybercrime threat actor first documentation
reportBlueVoyant (Thomas Elkins + Joshua Green): Casbaneiro Phishing Targets Latin America and Europe Using Dynamic PDF Lures (April 2026), canonical Horabot + WhatsApp + ClickFix disclosure
reportKaspersky: canonical 2025-2026 ClickFix social engineering Casbaneiro + Horabot deployment analysis
reportCointelegraph: ESET Flags New Latin American Banking Trojan That Targets Crypto (October 2019)
reportFortinet FortiGuard Labs: CHAVECLOAK 2024 analysis with Casbaneiro (Metamorfo/Ponteiro) reference
reportSCILabs Mexico: Casbaneiro Metamorpho tracking
reportMalpedia Software Profile: Metamorfo (= Casbaneiro)

Operational

State sponsor

Brazilian-origin organized cybercrime, recent industry tracking attributes to Augmented Marauder / Water Saci threat actor cluster (Trend Micro October 2025 + BlueVoyant April 2026). Operationally separate from state-sponsored APT activity. Attribution chain: (1) ESET canonical October 2019 first documentation: ESET WeLiveSecurity published "Casbaneiro: Dangerous cooking with a secret ingredient" by ESET Research Team, número dois ("number two") in canonical ESET Dirty Dozen Latin American banking trojan series.

Per ESET: "Casbaneiro, also known as Metamorfo, is a typical Latin American banking trojan that targets banks and cryptocurrency services in Brazil and Mexico. It uses the social engineering method... where fake pop-up windows are displayed." (2) MITRE ATT&CK S0455 Metamorfo canonical attribution: per MITRE ATT&CK: "Metamorfo is a Latin-American banking trojan operated by a Brazilian cybercrime group that has been active since at least April 2018. The group focuses on targeting banks and cryptocurrency services in Brazil and Mexico." (3) BitDefender canonical April 2020 disclosure: per Malpedia: "According to BitDefender, Metamorfo is a family of banker Trojans that has been active since mid-2018.

It primarily targets Brazilians and is delivered mostly through Office files rigged with macros in spam attachments." (4) ESET Dirty Dozen canonical December 15, 2021 retrospective: per ESET WeLiveSecurity "The Dirty Dozen of Latin America", Casbaneiro among 9 actively covered LATAM banking trojans. Per ESET 2021 telemetry: "Ousaban and Casbaneiro dominated Brazil in the latest months." (5) Casbaneiro = Amavaldo related family per ESET: per ESET: "We have also shown strong indicators leading us to believe that Casbaneiro is closely related to Amavaldo. Both pieces of malware use the same, uncommon cryptographic algorithm in the injector component, they have used a very similar PowerShell script in one of their campaigns and they have been seen distributing a very similar email tool." (6) Trend Micro October 2025 + BlueVoyant April 2026 Augmented Marauder / Water Saci attribution: per The Hacker News April 2026 (BlueVoyant Thomas Elkins + Joshua Green): "The activity has been attributed to a Brazilian cybercrime threat actor tracked as Augmented Marauder and Water Saci.

The e-crime group was first documented by Trend Micro in October 2025." Newer 2025-2026 attribution chain. (7) Fortinet 2024 industry coverage: per Fortinet CHAVECLOAK analysis: "Notable examples include Casbaneiro (Metamorfo/Ponteiro), Guildma, Mekotio, and Grandoreiro." Operational mission objective: Banking credential theft + cryptocurrency wallet theft via clipboard replacement + cryptocurrency service targeting. Per ESET: "monitoring the content of the clipboard and if the data seem to be a cryptocurrency wallet, it replaces them with the attacker's own.

" Operational target profile
  • Brazil + Mexico primary targets per ESET + MITRE ATT&CK S0455.
  • Banks + cryptocurrency services per ESET.
  • 2021 Brazil dominance per ESET telemetry (Ousaban + Casbaneiro dominated Brazil)
  • 2025-2026 expansion to Spanish-speaking Latin America + Europe per BlueVoyant April 2026 The cluster fills the Amavaldo-related-family + AES-256-SynCrypto-encryption + WhatsApp-Web-Horabot- ClickFix-2025-evolution position in the Latin American banking trojan operators cell.
Motivations
banking_credential_theft_brazil_mexico_targeting, cryptocurrency_service_targeting_capability, bitcoin_wallet_clipboard_hijack_capability, amavaldo_related_family_cryptographic_lineage, c2_hiding_via_remotely_stored_documents_fake_dns_legitimate_websites_signature, 2025_2026_horabot_whatsapp_clickfix_evolution_capability, augmented_marauder_water_saci_brazilian_cybercrime_threat_actor_attribution
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)59/60 · 98%
Analytics (MITRE CAR)25/60 · 41%
Runtime / container (Falco)7/60 · 11%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)16/60 · 26%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

0 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MAVERICK BANKING TROJAN WHATSAPP DISTRIBUTION ADJACENTMETAMORFO MALWARESPANISH JUDICIAL SUMMONS IMPERSONATION PHISHING PDF
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin