Casbaneiro / Metamorfo
Casbaneiro (canonical ESET naming per October 3, 2019 "Dangerous cooking with a secret ingredient" disclosure, número dois in ESET Dirty Dozen Latin American banking trojan series) / Metamorfo (alternative BitDefender + MITRE ATT&CK S0455 naming) / Ponteiro (Fortinet alternative naming) is a Brazilian-origin Latin American banking trojan active since at least April 2018 per MITRE ATT&CK S0455 attribution + BitDefender mid-2018 tracking; Brazilian-origin organized cybercrime attribution via ESET canonical October 2019 first documentation ("Casbaneiro, also known as Metamorfo, is a typical Latin American banking trojan that targets banks and cryptocurrency services in Brazil and Mexico") + MITRE ATT&CK S0455 canonical attribution ("Metamorfo is a Latin-American banking trojan operated by a Brazilian cybercrime group that has been active since at least April 2018") + BitDefender April 3, 2020 canonical disclosure (C. Erlich "The Avast Abuser: Metamorfo Banking" per Malpedia: "Metamorfo is a family of banker Trojans that has been active since mid-2018. It primarily targets Brazilians and is delivered mostly through Office files rigged with macros in spam attachments") + ESET Dirty Dozen canonical December 15, 2021 retrospective with Casbaneiro Brazil dominance per telemetry ("Ousaban and Casbaneiro dominated Brazil in the latest months") + Trend Micro October 2025 Augmented Marauder / Water Saci first documentation + BlueVoyant April 2026 canonical Horabot + WhatsApp Web + ClickFix disclosure (Thomas Elkins + Joshua Green via The Hacker News)
standalone malware platform cluster paralleling javali + melcoz + mispadu in v0.1.139 LATAM banking trojan operators cell expansion.
operational target profile Brazil + Mexico (primary historical targets) + 2025-2026 expansion to Spanish-speaking Latin America + Europe per BlueVoyant.
operational attack architecture: (1) Office files with macros in spam attachments primary distribution per BitDefender.
(2) fake banking pop-up overlay credential capture typical LATAM banking trojan tradecraft + screen capture + mouse/keyboard simulation + keystroke capture.
(3) cluster-defining AES-256 + SynCrypto Delphi library + SHA-256 password-derived key encryption per ESET ("Commands received from the C&C server are encrypted using AES-256. The SynCrypto Delphi library is used. The AES key is derived via SHA-256 from a password stored in the binary")
(4) Bitcoin wallet clipboard replacement hijack cluster-cell coherent with Melcoz + Grandoreiro + Mispadu crypto theft tradecraft.
(5) cluster-defining C2 hiding via remotely stored documents + legitimate + fake websites + fake DNS entries per ESET.
(6) cluster-defining Amavaldo-related family signature per ESET ("Casbaneiro is closely related to Amavaldo. Both pieces of malware use the same, uncommon cryptographic algorithm in the injector component, they have used a very similar PowerShell script in one of their campaigns and they have been seen distributing a very similar email tool")
(7) Re- Loader cracking tool legitimate-install masquerade per ESET.
(8) Delphi programming language origin signature.
2025-2026 evolution tradecraft (cluster- defining newer capabilities): (9) Horabot propagation mechanism per BlueVoyant April 2026 ("Casbaneiro's Delphi DLL module contacts a command-and-control C2 server to fetch a PowerShell script that employs Horabot to distribute the malware via phishing emails to harvested contacts from Microsoft Outlook")
(10) WhatsApp Web distribution vector per BlueVoyant ("Water Saci has a history of using WhatsApp Web as a distribution vector for disseminating banking trojans like Maverick and Casbaneiro in a worm-like manner"); (11) ClickFix social engineering per Kaspersky ("recent campaigns highlighted by Kaspersky have leveraged the ClickFix social engineering tactic to dupe users into running malicious HTA files with the end goal of deploying Casbaneiro and the Horabot spreader")
(12) dynamic PDF generation impersonating Spanish judicial summons signature per BlueVoyant April 2026 ("Rather than distributing a static file or hardcoded link as seen in older Horabot campaigns, this script initiates an HTTP POST request to a remote PHP API... The server dynamically forges a bespoke, password-protected PDF impersonating a Spanish judicial summons, which is returned to the infected host")
cluster fills the Amavaldo-related-family + AES-256-SynCrypto-encryption + cryptocurrency-service-targeting + WhatsApp-Web- Horabot-ClickFix-2025-2026-evolution position in Latin American banking trojan operators cell; canonical illustration of ESET Dirty Dozen LATAM banking trojan + AES-256 SynCrypto encryption + Amavaldo-related-family cryptographic lineage + C2 hiding via legitimate services + 2025-2026 Horabot/ WhatsApp/ClickFix evolution cited in essentially all subsequent Latin American banking trojan industry analyses through 2018-2026 period.