Also known as: Casbaneiro
Executive Summary
Metamorfo (alias Casbaneiro) is a Brazilian banking Trojan active since 2018 that targets banks and cryptocurrency services in Brazil and Mexico. Public reports indicate it harvests online banking credentials and exfiltrates sensitive data, although specific technical details remain limited. Security teams should prioritize monitoring for suspicious Windows processes, C2 communications, and phishing activity linked to this threat family.
Enhanced Description
Metamorfo, also known by the alias Casbaneiro, is a Windows‑based banking Trojan that has been linked to a Brazilian cybercrime group active since at least April 2018, according to reports from ESET (April 2020) and Medium. The gang focuses on financial institutions and cryptocurrency services in Brazil and Mexico, leveraging phishing campaigns, malicious links, or compromised web infrastructure to deliver the payload. While detailed technical analyses are sparse, public sources suggest that Metamorfo is designed to capture monetary credentials—such as online banking logins—and exfiltrate sensitive data for illicit use. Like many modern banking Trojans, Metamorfo likely employs a combination of stealthy persistence mechanisms and command‑and‑control communication channels. It may establish persistence via registry or scheduled task entries, while exfiltrating stolen credentials through encrypted tunnels to its C2 infrastructure. The malware’s behavior is tailored to infiltrate the highly regulated finance sector in Latin America, allowing attackers to siphon funds from bank accounts or gain control over cryptocurrency wallets. The threat actor behind Metamorfo demonstrates a clear preference for targeted attacks against local financial ecosystems, which increases exposure for entities operating within those markets. The limited public information on this family underscores the need for heightened vigilance and thorough endpoint monitoring—especially in environments where users may encounter social‑engineering attempts or compromised third‑party vendors. Given the small amount of publicly available evidence, analysts should treat Metamorfo’s capabilities as probable rather than confirmed until corroborated by forensic samples or threat‑intel feeds.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The available intelligence on Metamorfo is derived primarily from high‑level security advisories; there is an absence of publicly released malware samples or detailed technical analyses. Consequently, confidence in specific capabilities (e.g., keylogging, PowerShell use) remains moderate and is based on typical behaviors observed across similar banking Trojans. Further investigation into C2 infrastructure, code signatures, and deployment mechanisms is needed to confirm these attributes.
Metamorfo is a Latin-American banking trojan operated by a Brazilian cybercrime group that has been active since at least April 2018. The group focuses on targeting banks and cryptocurrency services in Brazil and Mexico.(Citation: Medium Metamorfo Apr 2020)(Citation: ESET Casbaneiro Oct 2019)