Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware Metamorfo

Metamorfo

TLP:CLEAR
Family

Also known as: Casbaneiro

AI Analysis

· 1 day ago

Executive Summary

Metamorfo (alias Casbaneiro) is a Brazilian banking Trojan active since 2018 that targets banks and cryptocurrency services in Brazil and Mexico. Public reports indicate it harvests online banking credentials and exfiltrates sensitive data, although specific technical details remain limited. Security teams should prioritize monitoring for suspicious Windows processes, C2 communications, and phishing activity linked to this threat family.

Enhanced Description

Metamorfo, also known by the alias Casbaneiro, is a Windows‑based banking Trojan that has been linked to a Brazilian cybercrime group active since at least April 2018, according to reports from ESET (April 2020) and Medium. The gang focuses on financial institutions and cryptocurrency services in Brazil and Mexico, leveraging phishing campaigns, malicious links, or compromised web infrastructure to deliver the payload. While detailed technical analyses are sparse, public sources suggest that Metamorfo is designed to capture monetary credentials—such as online banking logins—and exfiltrate sensitive data for illicit use. Like many modern banking Trojans, Metamorfo likely employs a combination of stealthy persistence mechanisms and command‑and‑control communication channels. It may establish persistence via registry or scheduled task entries, while exfiltrating stolen credentials through encrypted tunnels to its C2 infrastructure. The malware’s behavior is tailored to infiltrate the highly regulated finance sector in Latin America, allowing attackers to siphon funds from bank accounts or gain control over cryptocurrency wallets. The threat actor behind Metamorfo demonstrates a clear preference for targeted attacks against local financial ecosystems, which increases exposure for entities operating within those markets. The limited public information on this family underscores the need for heightened vigilance and thorough endpoint monitoring—especially in environments where users may encounter social‑engineering attempts or compromised third‑party vendors. Given the small amount of publicly available evidence, analysts should treat Metamorfo’s capabilities as probable rather than confirmed until corroborated by forensic samples or threat‑intel feeds.

Key Capabilities

  • Credential harvesting from banking websites
  • Form grabbing and keylogging for credential theft
  • Persistent execution via registry or scheduled tasks
  • Encrypted command‑and‑control communication to exfiltrate data
  • Remote process injection or DLL side‑loading for persistence
  • Potential use of PowerShell for download and execution

ATT&CK Techniques

T1059.001 PowerShell
T1056.001 Keylogging
T1074.001 Local Data Staging
T1078 Valid Accounts
T1041 Exfiltration Over Command and Control Channel
T1055 Process Injection

Recommended Actions

  • Deploy next‑generation antivirus with real‑time detection for known banking Trojan indicators (file hashes, PE characteristics)
  • Implement network segmentation and strict egress controls around banking applications to reduce lateral movement
  • Enforce multi‑factor authentication on all financial system logins and monitor for credential misuse
  • Patch Windows systems promptly to close known vulnerabilities that could be leveraged by trojan delivery vectors
  • Educate users about phishing emails, malicious links, and the dangers of unverified third‑party attachments

Suggested Tags

Banking Trojan
Brazilian Cybercrime Group
Latium Threat Actor
Cryptocurrency Targeting
Threat Family Metamorfo

Confidence Assessment

The available intelligence on Metamorfo is derived primarily from high‑level security advisories; there is an absence of publicly released malware samples or detailed technical analyses. Consequently, confidence in specific capabilities (e.g., keylogging, PowerShell use) remains moderate and is based on typical behaviors observed across similar banking Trojans. Further investigation into C2 infrastructure, code signatures, and deployment mechanisms is needed to confirm these attributes.

Description

Metamorfo is a Latin-American banking trojan operated by a Brazilian cybercrime group that has been active since at least April 2018. The group focuses on targeting banks and cryptocurrency services in Brazil and Mexico.(Citation: Medium Metamorfo Apr 2020)(Citation: ESET Casbaneiro Oct 2019)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.