Skip to content

Metamorfo

Casbaneiro, also known as Metamorfo, is a Windows banking Trojan targeting online-banking users in Latin America, including victims in Argentina, Peru, Colombia, and Mexico.

Profile source: Mallory opens in a new tab

Metamorfo

Family profile

Casbaneiro, also known as Metamorfo, is a Windows banking Trojan targeting online-banking users in Latin America, including victims in Argentina, Peru, Colombia, and Mexico. It is distributed through phishing emails using invoice- and legal-notice-themed PDF lures. Recent delivery chains have used an HTA downloader and separately retrieved AutoIt components to unpack and launch the final payload.

Casbaneiro establishes persistence using a Windows Startup-folder shortcut and uses process injection to execute its payload within legitimate Windows processes. It employs anti-analysis measures including geographic filtering of delivery, language-based execution restrictions, runtime reconstruction and decryption of configuration strings, and communication workflows intended to complicate automated inspection and network analysis.

The malware collects victim and system information, including Microsoft Outlook address-book entries and email sender and recipient metadata, and exfiltrates collected data to attacker-controlled infrastructure. It delays primary command-and-control activity until the victim accesses a targeted banking website. During targeted online-banking sessions, it can support fraud through fake banking windows, clipboard manipulation, keyboard control, file execution, and command execution. No specific threat actor attribution is established.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Persistence
  • Post Exploitation
  • Process Injection
  • Reconnaissance
  • Spoofing

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 14, 2026
Last activity
Sep 14, 2026
Feed role
C2
Host form
0 IP / 2 hostnames

Leading locations

  • BR1
  • US1

Leading providers

  • Cloudflare, Inc.1
  • Servicos de Infraestrutura e Datacenter1

Infrastructure traits

  • Hosting 2
  • Anycast 1

Reported operators

Threat actors

2 named in public reporting
Water Saci

Several behaviors in this sample are similar to those observed in the Casbaneiro (Metamorfo) banking malware lineage.

Augmented Marauder

The point of all this is to drop Casbaneiro, a classic banking Trojan that triggers when victims visit their cryptocurrency or financial service providers online.

MITRE ATT&CK

Metamorfo in ATT&CK

94 distinct techniques

Techniques

94 techniques
T1480.001 Environmental Keying T1204.002 Malicious File T1140 Deobfuscate/Decode Files or Information T1566.001 Spearphishing Attachment T1497 Virtualization/Sandbox Evasion T1547.001 Registry Run Keys / Startup Folder T1115 Clipboard Data T1055 Process Injection T1114.001 Local Email Collection T1041 Exfiltration Over C2 Channel T1036 Masquerading T1614.001 System Language Discovery T1480.002 Mutual Exclusion T1027 Obfuscated Files or Information T1105 Ingress Tool Transfer T1218.005 Mshta T1082 System Information Discovery T1059 Command and Scripting Interpreter T1071.001 Web Protocols T1001 Data Obfuscation T1566.002 Spearphishing Link T1497.001 System Checks T1480 Execution Guardrails T1547.009 Shortcut Modification T1033 System Owner/User Discovery T1114 Email Collection T1132.001 Standard Encoding T1189 Drive-by Compromise T1056 Input Capture T1071 Application Layer Protocol T1059.003 Windows Command Shell T1113 Screen Capture T1055.012 Process Hollowing T1112 Modify Registry T1518 Software Discovery T1047 Windows Management Instrumentation T1518.001 Security Software Discovery T1219 Remote Access Tools T1057 Process Discovery T1071.003 Mail Protocols T1059.005 Visual Basic T1566 Phishing T1010 Application Window Discovery T1204 User Execution T1539 Steal Web Session Cookie T1218.007 Msiexec T1083 File and Directory Discovery T1106 Native API T1124 System Time Discovery T1560 Archive Collected Data T1564.003 Hidden Window T1056.001 Keylogging T1070.004 File Deletion T1059.007 JavaScript T1573 Encrypted Channel T1547 Boot or Logon Autostart Execution T1059.001 PowerShell T1218.011 Rundll32 T1053.005 Scheduled Task T1555.003 Credentials from Web Browsers T1197 BITS Jobs T1056.002 GUI Input Capture T1027.001 Binary Padding T1048 Exfiltration Over Alternative Protocol T1571 Non-Standard Port T1132.002 Non-Standard Encoding T1036.005 Match Legitimate Resource Name or Location T1552.001 Credentials In Files T1568.003 DNS Calculation T1562 Impair Defenses T1119 Automated Collection T1213 Data from Information Repositories T1036.003 Rename Legitimate Utilities T1070.009 Clear Persistence T1027.013 Encrypted/Encoded File T1070 Indicator Removal T1553.002 Code Signing T1562.001 Disable or Modify Tools T1056.003 Web Portal Capture T1204.001 Malicious Link T1078 Valid Accounts T1027.002 Software Packing T1129 Shared Modules T1574 Hijack Execution Flow T1573.002 Asymmetric Cryptography T1027.003 Steganography T1095 Non-Application Layer Protocol T1555 Credentials from Password Stores T1055.001 Dynamic-link Library Injection T1565.002 Transmitted Data Manipulation T1573.001 Symmetric Cryptography T1574.001 DLL T1102.001 Dead Drop Resolver T1102.003 One-Way Communication

Reporting

Research mentioning Metamorfo

Aug 31
Splunk Research

Detection: MacOS Osascript Displaying Suspicious User Prompt | Splunk Security Content

Splunk Enterprise Security released an anomaly analytic to identify suspicious macOS osascript executions that invoke AppleScript display alert or display dialog commands using credential- or security-themed wording. Such dialogs can impersonate macOS authentication or security notices and trick users into disclosing passwords and other sensitive data, a technique tracked as MITRE ATT&CK T1056.002 (GUI Input Capture). The detection uses osquery process telemetry, maps the execution mechanism to T1059.002 (AppleScript), and generates intermediate risk events rather than notable findings; it is disabled by default. osascript is a legitimate native macOS utility but can also execute AppleScript or JavaScript for Automation to collect clipboard or system data, manipulate applications, and present fake authentication prompts, so alerts require investigation to distinguish malicious activity from legitimate MDM, deployment, support, and automation scripts.

Aug 15
Github Web

GitHub - tjnel/certgraveyard_yara: Automated YARA rule generation from the Cert Central compromised certificate database. · GitHub

A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.

Aug 13
Malware News

Armored Likho expands its cyber-espionage toolkit - Malware News - Malware Analysis, News and Indicators

Armored Likho, also tracked as Eagle Werewolf, launched a cyber-espionage campaign against private users and organizations in Russia, including targets in government, corporate, IT, and education sectors. The operation used fake charity-assistance applications built as Rust/Tauri droppers to install a new modular espionage framework called Still Toolkit. Its Still Sync component steals Telegram Desktop session data, authenticates to victims’ Telegram accounts, and exfiltrates chats, media, and account details through the Telegram API, while Still Audio covertly activates microphone surveillance by detecting speech and uploading recordings to command-and-control servers.

Aug 13
Securelist Ru

Новые инструменты Armored Likho нацелены на Telegram и прослушку | Securelist

Aug 13
Securelist

New Armored Likho tools target Telegram and eavesdropping | Securelist

Aug 11
Lazarusholic Bluesky

Post by @lazarusholic.bsky.social - Bluesky

A Sonatype report identified six malicious npm packages that used Ethereum transactions to retrieve and stage malicious payloads, an unusual delivery method that obscures second-stage infrastructure behind blockchain activity. The campaign was linked in public reporting to ContagiousInterview and NullReceiver, indicating continued abuse of the JavaScript and Node.js ecosystem for software supply-chain compromise. The activity aligns with broader attacker tradecraft documented for MITRE ATT&CK T1059.007 (Command and Scripting Interpreter: JavaScript), which covers JavaScript and Node.js use for payload delivery, execution, reconnaissance, and command-and-control. Defenders monitoring follow-on behavior should watch for suspicious child-process activity and discovery commands launched from non-shell parent processes, a pattern reflected in Splunk detection guidance for tools such as ipconfig.exe, systeminfo.exe, net.exe, and whoami.exe executed outside normal cmd.exe or PowerShell chains.

Jul 28
Sekoia

Exposing FakeBat loader: distribution methods and adversary infrastructure

Jul 15
Esentire

DinDoor, DenoRAT, and NightshadeC2: Analyzing TAG-150's Evolving Tradecraft | eSentire

eSentire reported that a June 2026 intrusion against a finance-sector customer began with a ClickFix-style social engineering lure that triggered a malicious command, an MSI installer, and a multi-stage malware chain attributed to TAG-150. The infection sequence used an apparently AI-generated PowerShell script, Griffin20.ps1, to install the Deno runtime and launch the Deno-based loader DinDoor, which then deployed DenoRAT and ultimately NightshadeC2. Investigators said the malware communicated with command-and-control infrastructure including webstizkgao[.]com and used hard-coded JWTs carrying campaign identifiers such as buildId 0def066f14754be9 and buildNote LearnV7msi. The tooling provided broad post-compromise capability, with DenoRAT functioning as a RAT, loader, and stealer that supported command execution, persistence, host fingerprinting, file operations, screenshots, PTY and VNC-style remote control, and theft from browsers and cryptocurrency wallets. eSentire said the malware could also bypass Chromium App-Bound Encryption through DLL injection, a technique widely associated with in-memory execution, evasion, and abuse of legitimate Windows processes in ATT&CK T1055.001. The final NightshadeC2 payload was delivered through a PowerShell-driven Python in-memory loader, decrypted from an encrypted container using AES-256-CBC with a key derived from MoscauHighSmoke, and reflectively mapped into a Python process before the affected host was isolated and remediated.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.