Last seven days
- First activity
- Sep 14, 2026
- Last activity
- Sep 14, 2026
- Feed role
- C2
- Host form
- 0 IP / 2 hostnames
Casbaneiro, also known as Metamorfo, is a Windows banking Trojan targeting online-banking users in Latin America, including victims in Argentina, Peru, Colombia, and Mexico.
Profile source: Mallory opens in a new tabMetamorfo
Casbaneiro, also known as Metamorfo, is a Windows banking Trojan targeting online-banking users in Latin America, including victims in Argentina, Peru, Colombia, and Mexico. It is distributed through phishing emails using invoice- and legal-notice-themed PDF lures. Recent delivery chains have used an HTA downloader and separately retrieved AutoIt components to unpack and launch the final payload.
Casbaneiro establishes persistence using a Windows Startup-folder shortcut and uses process injection to execute its payload within legitimate Windows processes. It employs anti-analysis measures including geographic filtering of delivery, language-based execution restrictions, runtime reconstruction and decryption of configuration strings, and communication workflows intended to complicate automated inspection and network analysis.
The malware collects victim and system information, including Microsoft Outlook address-book entries and email sender and recipient metadata, and exfiltrates collected data to attacker-controlled infrastructure. It delays primary command-and-control activity until the victim accesses a targeted banking website. During targeted online-banking sessions, it can support fraud through fake banking windows, clipboard manipulation, keyboard control, file execution, and command execution. No specific threat actor attribution is established.
C2 tracking
Derp observations, rolling seven-day window
Reported operators
Several behaviors in this sample are similar to those observed in the Casbaneiro (Metamorfo) banking malware lineage.
The point of all this is to drop Casbaneiro, a classic banking Trojan that triggers when victims visit their cryptocurrency or financial service providers online.
MITRE ATT&CK
Reporting
Splunk Enterprise Security released an anomaly analytic to identify suspicious macOS osascript executions that invoke AppleScript display alert or display dialog commands using credential- or security-themed wording. Such dialogs can impersonate macOS authentication or security notices and trick users into disclosing passwords and other sensitive data, a technique tracked as MITRE ATT&CK T1056.002 (GUI Input Capture). The detection uses osquery process telemetry, maps the execution mechanism to T1059.002 (AppleScript), and generates intermediate risk events rather than notable findings; it is disabled by default. osascript is a legitimate native macOS utility but can also execute AppleScript or JavaScript for Automation to collect clipboard or system data, manipulate applications, and present fake authentication prompts, so alerts require investigation to distinguish malicious activity from legitimate MDM, deployment, support, and automation scripts.
A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.
Armored Likho, also tracked as Eagle Werewolf, launched a cyber-espionage campaign against private users and organizations in Russia, including targets in government, corporate, IT, and education sectors. The operation used fake charity-assistance applications built as Rust/Tauri droppers to install a new modular espionage framework called Still Toolkit. Its Still Sync component steals Telegram Desktop session data, authenticates to victims’ Telegram accounts, and exfiltrates chats, media, and account details through the Telegram API, while Still Audio covertly activates microphone surveillance by detecting speech and uploading recordings to command-and-control servers.
A Sonatype report identified six malicious npm packages that used Ethereum transactions to retrieve and stage malicious payloads, an unusual delivery method that obscures second-stage infrastructure behind blockchain activity. The campaign was linked in public reporting to ContagiousInterview and NullReceiver, indicating continued abuse of the JavaScript and Node.js ecosystem for software supply-chain compromise. The activity aligns with broader attacker tradecraft documented for MITRE ATT&CK T1059.007 (Command and Scripting Interpreter: JavaScript), which covers JavaScript and Node.js use for payload delivery, execution, reconnaissance, and command-and-control. Defenders monitoring follow-on behavior should watch for suspicious child-process activity and discovery commands launched from non-shell parent processes, a pattern reflected in Splunk detection guidance for tools such as ipconfig.exe, systeminfo.exe, net.exe, and whoami.exe executed outside normal cmd.exe or PowerShell chains.
eSentire reported that a June 2026 intrusion against a finance-sector customer began with a ClickFix-style social engineering lure that triggered a malicious command, an MSI installer, and a multi-stage malware chain attributed to TAG-150. The infection sequence used an apparently AI-generated PowerShell script, Griffin20.ps1, to install the Deno runtime and launch the Deno-based loader DinDoor, which then deployed DenoRAT and ultimately NightshadeC2. Investigators said the malware communicated with command-and-control infrastructure including webstizkgao[.]com and used hard-coded JWTs carrying campaign identifiers such as buildId 0def066f14754be9 and buildNote LearnV7msi. The tooling provided broad post-compromise capability, with DenoRAT functioning as a RAT, loader, and stealer that supported command execution, persistence, host fingerprinting, file operations, screenshots, PTY and VNC-style remote control, and theft from browsers and cryptocurrency wallets. eSentire said the malware could also bypass Chromium App-Bound Encryption through DLL injection, a technique widely associated with in-memory execution, evasion, and abuse of legitimate Windows processes in ATT&CK T1055.001. The final NightshadeC2 payload was delivered through a PowerShell-driven Python in-memory loader, decrypted from an encrypted container using AES-256-CBC with a key derived from MoscauHighSmoke, and reflectively mapped into a Python process before the affected host was isolated and remediated.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.