Casbaneiro banking trojan distribution via dynamic PDF lures and Horabot propagation
Summary
Hide ▲
Show ▼
A phishing campaign attributed to the Brazilian cybercrime group Augmented Marauder (Water Saci) is actively targeting Spanish-speaking users in Latin America and Europe to deliver the Casbaneiro (Metamorfo) Windows banking trojan and the Horabot malware family. The campaign leverages court summons-themed phishing emails with password-protected PDF attachments that redirect to malicious downloads, initiating a multi-stage infection chain involving HTA, VBS, AutoIt loaders, and dynamic PDF generation for further propagation. The attack infrastructure combines WhatsApp automation, ClickFix social engineering, and enterprise email hijacking to distribute Casbaneiro as the primary payload while Horabot acts as a propagation mechanism targeting Outlook contacts and email accounts.
Timeline
-
01.04.2026 15:36 1 articles · 2h ago
Casbaneiro and Horabot phishing campaign expands to Europe with dynamic PDF lures and Outlook hijacking
A Brazilian cybercrime group tracked as Augmented Marauder (Water Saci) is distributing Casbaneiro and Horabot malware via court summons-themed phishing emails containing password-protected PDF attachments. The infection chain involves malicious ZIP downloads leading to HTA/VBS execution, AutoIt loaders, and dynamic generation of PDF lures via a remote PHP API. Horabot is used to propagate malware through compromised Outlook contacts and hijacked email accounts (Yahoo, Live, Gmail), expanding beyond prior Latin America-focused operations into Europe.
Show sources
- Casbaneiro Phishing Targets Latin America and Europe Using Dynamic PDF Lures — thehackernews.com — 01.04.2026 15:36
Information Snippets
-
The campaign begins with court summons-themed phishing emails containing password-protected PDF attachments that include embedded malicious links.
First reported: 01.04.2026 15:361 source, 1 articleShow sources
- Casbaneiro Phishing Targets Latin America and Europe Using Dynamic PDF Lures — thehackernews.com — 01.04.2026 15:36
-
Clicking the malicious link triggers an automatic download of a ZIP archive, which executes interim HTA and VBS payloads after environment checks for antivirus software such as Avast.
First reported: 01.04.2026 15:361 source, 1 articleShow sources
- Casbaneiro Phishing Targets Latin America and Europe Using Dynamic PDF Lures — thehackernews.com — 01.04.2026 15:36
-
The VBS payload retrieves next-stage components including AutoIt-based loaders that extract encrypted payload files with extensions ".ia" or ".at" to deploy Casbaneiro ("staticdata.dll") and Horabot ("at.dll").
First reported: 01.04.2026 15:361 source, 1 articleShow sources
- Casbaneiro Phishing Targets Latin America and Europe Using Dynamic PDF Lures — thehackernews.com — 01.04.2026 15:36
-
Casbaneiro contacts a C2 server to fetch a PowerShell script that uses Horabot to propagate via phishing emails sent from the compromised host’s Outlook to harvested contacts.
First reported: 01.04.2026 15:361 source, 1 articleShow sources
- Casbaneiro Phishing Targets Latin America and Europe Using Dynamic PDF Lures — thehackernews.com — 01.04.2026 15:36
-
The PowerShell script dynamically generates a bespoke, password-protected PDF impersonating a Spanish judicial summons via HTTP POST to a remote PHP API endpoint, which is then attached to phishing emails.
First reported: 01.04.2026 15:361 source, 1 articleShow sources
- Casbaneiro Phishing Targets Latin America and Europe Using Dynamic PDF Lures — thehackernews.com — 01.04.2026 15:36
-
A secondary Horabot DLL (".at.dll") functions as a spam and account hijacking tool targeting Yahoo, Live, and Gmail accounts to send phishing emails via Outlook.
First reported: 01.04.2026 15:361 source, 1 articleShow sources
- Casbaneiro Phishing Targets Latin America and Europe Using Dynamic PDF Lures — thehackernews.com — 01.04.2026 15:36
-
The threat actor Augmented Marauder (Water Saci), first documented by Trend Micro in October 2025, employs WhatsApp automation, ClickFix tactics, and email hijacking infrastructure for distribution.
First reported: 01.04.2026 15:361 source, 1 articleShow sources
- Casbaneiro Phishing Targets Latin America and Europe Using Dynamic PDF Lures — thehackernews.com — 01.04.2026 15:36
-
Horabot has been used in attacks against Latin America since at least November 2020 and is known to distribute banking trojans like Maverick and Casbaneiro via WhatsApp Web in worm-like fashion.
First reported: 01.04.2026 15:361 source, 1 articleShow sources
- Casbaneiro Phishing Targets Latin America and Europe Using Dynamic PDF Lures — thehackernews.com — 01.04.2026 15:36