Casbaneiro is the Hook in Alt-Coin Phishing

Stu Sjouwerman | Oct 9, 2019

PhishingOneMinuteThe Casbaneiro banking Trojan is going after Latin American victims’ cryptocurrency, Verdict reports. It’s being distributed via phishing emails which trick victims into downloading a malicious ZIP file. In some cases, this ZIP file is made out to be Spotify, OneDrive, or WhatsApp applications.

Once a system is infected, Casbaneiro will look for the presence of Latin American banking applications. If the victim uses one of these applications, the malware will trigger spoofed popup windows to intercept the users’ banking information. The malware also acts as a keylogger and can take screenshots.

Additionally, Casbaneiro monitors the victim’s clipboard for content that looks like a Bitcoin address. If it detects one, it will replace it with an address belonging to the attacker. As a result, the victim will accidentally send their cryptocurrency to the attacker’s address. Verdict noted that one of the addresses used by Casbaneiro has received fifty-two payments in Bitcoin, totaling around $10,200.

The malware primarily targets Portuguese and Spanish-speaking people, and it’s most active in Brazil and Mexico. It’s also been observed going after targets in Argentina, Peru, Spain, and the United States.

It can be very hard to detect and remove banking malware after it’s already compromised your system, so it’s best to prevent it from gaining access in the first place. New-school security awareness training can help you and your employees identify and thwart phishing emails and other social engineering attacks.

Verdict has the story: https://www.verdict.co.uk/casbaneiro-malware/

 

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the human and AI workforce to make safer security decisions every day. Trusted by over 70,000 organizations worldwide, we help strengthen security culture and manage risk. Our comprehensive AI-driven platform includes awareness and compliance training, cloud email security, real-time coaching, crowdsourced anti-phishing, AI Defense Agents, agent security and more. As the only global security platform of its kind, KnowBe4 provides personalized content, tools, and techniques to keep the modern workforce safe from phishing, vishing, deepfakes, and emerging threats.

Get the latest insights, trends and security news. Subscribe to CyberheistNews.