Home/Threat Actor/Krachulka
Threat Actor

Krachulka

krachulka · brazil · active since 2018-01

Krachulka is a smaller Brazilian-origin banking trojan family operationally tracked by ESET researchers as part of the broader Brazilian-origin banking trojan family ecosystem.

operates with Brazilian Portuguese language spam email distribution, banking website overlay attacks against Brazilian banking institutions, keystroke logging, screen capture, and clipboard hijacking for transaction redirection, operational tradecraft consistent with ecosystem baseline.

does not display significantly distinctive operational tradecraft beyond Brazilian-origin banking malware ecosystem baseline.

primary targeting of Brazilian banking customers with selective Latin American expansion.

thin public technical documentation relative to larger families in the ecosystem.

curated for LATAM banking malware ecosystem completeness alongside Banbra, Bizarro, Casbaneiro, Grandoreiro, Guildma/Astaroth, Javali, Melcoz, Mekotio, Amavaldo, and additional Brazilian-origin banking trojan families in this corpus.

brazil confidence: medium 6 aliases
Sigma rules200 YARA rules0 Live IOCs0 CVEs exploited0

Profile

Krachulka is a smaller Brazilian-origin banking trojan family operationally tracked by ESET researchers as part of the broader ESET-led research initiative cataloguing Brazilian- origin banking trojan families across multiple years of operational tracking. The cluster operates within the broader Brazilian-origin banking malware ecosystem with operational characteristics consistent with the ecosystem baseline, Brazilian Portuguese language spam email distribution, banking website overlay attacks against Brazilian banking institutions, keystroke logging of banking authentication credentials, screen capture of banking session content, and clipboard hijacking for banking transaction redirection. Krachulka does not display significantly distinctive operational tradecraft beyond the Brazilian-origin banking malware ecosystem baseline, operationally distinct from Bizarro (which demonstrated European banking targeting expansion, MSI installer distribution tradecraft, and cloud storage C2 abuse, bizarro.yaml) and operationally distinct from the larger families with more operationally-significant public-record documentation (Banbra, Casbaneiro, Grandoreiro, Guildma / Astaroth, Mekotio).

The cluster is curated for LATAM banking malware ecosystem completeness as part of the broader Brazilian-origin banking trojan family panorama in this corpus. The entry is structurally significant for ecosystem completeness rather than for deep technical tradecraft analysis distinctiveness. Analysts requiring technical depth on the Brazilian banking malware ecosystem should prioritize the Banbra (banbra.yaml , foundational), Bizarro (bizarro.yaml, European expansion), Casbaneiro (casbaneiro.yaml), Grandoreiro (grandoreiro.yaml), Guildma / Astaroth (guildma_astaroth.yaml), and Mekotio (mekotio.yaml) entries.

Aliases

6
krachulkakrachulka operatorskrachulka banking trojankrachulka clusterkrachulka_brazilian_banking_clusterkrachulka latin american banking trojan

Notable Campaigns

2
2019-2024ESET Krachulka Banking Trojan Tracking and Documentation
2018-2025Krachulka Operational Position Within Brazilian-Origin Banking Malware Ecosystem

Attribution & Reporting

Attributed by
ESETKasperskyBrazilian Federal Police (Policia Federal)Trend MicroF-Secure (now WithSecure)
Key reporting
reportESET WeLiveSecurity: Krachulka Banking Trojan Analysis
reportESET WeLiveSecurity: Brazilian Banking Trojan Family Evolution Series
reportKaspersky Securelist: Brazilian Banking Trojan Ecosystem Coverage
reportTrend Micro: Brazilian Banking Malware Ecosystem Research
reportMalpedia Malware Profile: Krachulka

Operational

State sponsor

Cybercriminal cluster of Brazilian-origin operators responsible for developing, distributing, and operating the Krachulka banking trojan family, a smaller Brazilian- origin banking malware family operating within the broader Brazilian-origin banking trojan ecosystem. The cluster was tracked by ESET researchers and adjacent industry analysis as part of the broader ESET-led research initiative cataloguing Brazilian-origin banking trojan families across multiple years of operational tracking. Krachulka represents one of the smaller and operationally-thinner-documented families in the broader Brazilian-origin banking malware ecosystem, operationally distinct from but operating in parallel with the more operationally-significant families curated separately in this corpus including Banbra (banbra.yaml, foundational Brazilian banking trojan), Bizarro (bizarro.yaml, European targeting expansion), Casbaneiro (casbaneiro.yaml), Grandoreiro (grandoreiro.yaml), Guildma / Astaroth (guildma_astaroth.yaml), Javali (javali.yaml), Melcoz (melcoz.yaml), Mekotio (mekotio.yaml), and Amavaldo (amavaldo.yaml).

The cluster operators have not been individually indicted or publicly named. Industry analysis (ESET, Kaspersky, and selectively Brazilian Federal Police investigative reporting) has assessed the cluster as Brazilian-origin based on operational tradecraft characteristics consistent with the broader Brazilian- origin banking malware ecosystem, language localization (Brazilian Portuguese strings in malware samples), and operational targeting profile (overwhelming focus on Brazilian banking institutions and Brazilian banking customers). The cluster operates as a financially- motivated cybercriminal operation with no known state sponsorship.

Motivations
financial_gain, banking_credential_theft, banking_fraud_operations, brazilian_retail_banking_targeting
Sectors
Regions

Detection Blind Spots

51 techniques
Across this actor’s 51 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)47/51 · 92%
Analytics (MITRE CAR)17/51 · 33%
Runtime / container (Falco)7/51 · 13%
File / malware (YARA)1/51 · 1%
Network (Suricata/Snort)14/51 · 27%
Vuln scan (Nuclei)0/51 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

0 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
SPAM EMAIL DISTRIBUTION KITS
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin