Back to Intelligence

Casbaneiro Banking Trojan (Metamorfo/Ousaban) Distributed C2 Campaign: OTX Pulse Analysis — LATAM Financial Sector Detection Pack

SA
Security Arsenal Team
October 10, 2026
9 min read

Threat Summary

A live AlienVault OTX pulse documents an active Casbaneiro campaign observed in August 2026 targeting users across Argentina, Colombia, Mexico, and Peru — with the financial sector squarely in the crosshairs. Casbaneiro is a mature Latin American banking trojan family (tracked by MITRE as Metamorfo / S0455, with the related Ousaban variant) whose operators specialize in credential theft and banking fraud against regional financial institutions.

The attack chain is a multi-stage social-engineering operation:

  1. Phishing emails themed as fake invoices and legal notices, carrying malicious PDF attachments or links.
  2. PDFs/lures trigger an HTA downloader stage executed via mshta.exe.
  3. The HTA stage drops and invokes an AutoIt loader — a signature of the Casbaneiro/Metamorfo lineage — which decrypts and injects the final banking payload.
  4. Before full deployment, the malware performs geofencing: victim IP addresses are checked against target-country lists, and non-LATAM victims are discarded. This dramatically reduces sandbox and researcher visibility.
  5. Exfiltrated banking credentials and session data are pushed to distributed data-receiving servers — a C2 architecture deliberately spread across multiple nodes to survive takedowns and frustrate single-IOC blocking.

The objective is unambiguous: harvest online banking credentials and session tokens from LATAM financial services customers for account takeover and fraudulent wire transfer. For enterprises with LATAM subsidiaries, remote workers, or treasury operations in the region, this is a direct identity-risk event.

Threat Actor / Malware Profile

Malware families: Casbaneiro | Metamorfo (S0455) | Ousaban Attribution: Unknown financially-motivated LATAM-focused actor cluster

CapabilityDetail
DistributionSpear-phishing emails with invoice/legal-notice themed PDFs
Loader chainHTA downloader (mshta.exe) → AutoIt3 script loader → final payload injection
Payload behaviorBanking credential theft, overlay/fake login windows, keystroke and clipboard capture, screenshot harvesting
C2 communicationHTTP(S) to distributed data-receiving servers; infrastructure deliberately fragmented across multiple receiving nodes
GeofencingIP-based victim filtering — only Argentina, Colombia, Mexico, Peru victims receive full payload
Anti-analysisGeofence-based sandbox evasion, staged payloads, AutoIt-obfuscated loaders, distributed C2 to defeat takedown
PersistenceRegistry Run keys and/or scheduled tasks established by the loader stage

The AutoIt loader stage is a strong detection anchor: legitimate AutoIt usage in enterprise environments is rare, and AutoIt3.exe executing scripts from %TEMP%, %APPDATA%, or %PROGRAMDATA% shortly after an mshta.exe event is a high-fidelity Casbaneiro-family indicator.

IOC Analysis

The pulse contains 25 file-hash indicators, all SHA-256 hashes of campaign artifacts — phishing PDFs, HTA downloaders, AutoIt loaders, and compiled payloads. A representative sample:

  • 4302586202234cdf1ca058fd3c62be0050c8155ed113f3f62337d756e6915044
  • 47d321c1a232e5cdd1e39a06dadbd79114dc1a2f0f8eac289e6b653a5d126f95
  • 51503ce1373c7fa72a1da5c5c4b30f88c8224686669ba4b64196591414fdc64c
  • 5a76669ec410d0b3e21112a4a6fd3207976b299ee27c5fc3d42f2673170ab95e

How SOC teams should operationalize:

  • Hash blocking: Load all 25 SHA-256 indicators into your EDR blocklist (CrowdStrike, Defender for Endpoint, SentinelOne) and your secure email gateway's attachment-sandbox verdicts.
  • Retroactive hunting: Hash-only IOCs age poorly — loaders are repacked frequently. Pair hash matching with the behavioral detections below, which survive recompilation.
  • Tooling: Enrich hashes via VirusTotal, MalwareBazaar, and OTX pulse cross-referencing. Hash lookups against AutoIt-compiled samples often reveal embedded script strings; use strings + AutoIt decompilers (Exe2Aut / myAutToExe) to extract C2 URLs and geofence logic from any recovered samples.
  • Note on network IOCs: Because this campaign uses distributed data-receiving servers, network indicators rotate quickly. Behavioral network detection (HTA/AutoIt processes making outbound HTTP connections) is more durable than IP/domain lists.

Detection Engineering

YAML
---
title: Casbaneiro HTA Downloader Execution via Mshta Spawning Script or Loader Processes
id: 8f3a2c71-9c4d-4e1a-b6f2-casbhta00001
status: experimental
description: Detects mshta.exe executing .hta content and spawning child processes consistent with the Casbaneiro/Metamorfo phishing-to-HTA downloader stage observed targeting LATAM finance users.
author: Security Arsenal Threat Intelligence
references:
  - https://www.fortinet.com/blog/threat-research/casbaneiro-a-banking-trojan-with-distributed-data-receiving-servers
date: 2026/10/10
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|endswith: '\mshta.exe'
  selection_child:
    Image|endswith:
      - '\powershell.exe'
      - '\cmd.exe'
      - '\wscript.exe'
      - '\cscript.exe'
      - '\rundll32.exe'
      - '\AutoIt3.exe'
      - '\certutil.exe'
      - '\bitsadmin.exe'
  filter_rare_enterprise:
    CommandLine|contains:
      - 'cti'  # placeholder for known enterprise HTA tools; tune per environment
  condition: selection_parent and selection_child and not filter_rare_enterprise
falsepositives:
  - Legacy enterprise HTA applications (rare in modern environments)
level: high
tags:
  - attack.initial_access
  - attack.t1566.001
  - attack.execution
  - attack.t1218.005
---
title: Suspicious AutoIt3 Loader Execution from User-Writable Directories
id: 8f3a2c71-9c4d-4e1a-b6f2-casbauto0002
status: experimental
description: Detects AutoIt3.exe executing scripts from temp or user-profile paths, a hallmark of Casbaneiro/Metamorfo/Ousaban loader stages.
author: Security Arsenal Threat Intelligence
references:
  - https://www.fortinet.com/blog/threat-research/casbaneiro-a-banking-trojan-with-distributed-data-receiving-servers
date: 2026/10/10
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    Image|endswith: '\AutoIt3.exe'
  selection_path:
    CommandLine|contains:
      - '\AppData\'
      - '\Temp\'
      - '\ProgramData\'
      - '\Users\Public\'
  condition: selection_img and selection_path
falsepositives:
  - Legitimate AutoIt-based software deployment tooling (uncommon; whitelist by signer and path)
level: high
tags:
  - attack.execution
  - attack.t1059
  - attack.defense_evasion
  - attack.t1027
---
title: Script Interpreter or AutoIt Process Outbound HTTP to Rare External Host
id: 8f3a2c71-9c4d-4e1a-b6f2-casbc200003
status: experimental
description: Detects mshta.exe, wscript/cscript, or AutoIt3.exe initiating outbound HTTP(S) connections, consistent with Casbaneiro geofencing checks and distributed data-receiving server communication.
author: Security Arsenal Threat Intelligence
references:
  - https://www.fortinet.com/blog/threat-research/casbaneiro-a-banking-trojan-with-distributed-data-receiving-servers
date: 2026/10/10
logsource:
  category: network_connection
  product: windows
detection:
  selection:
    Image|endswith:
      - '\mshta.exe'
      - '\AutoIt3.exe'
      - '\wscript.exe'
      - '\cscript.exe'
    DestinationPort:
      - 80
      - 443
      - 8080
  filter_internal:
    DestinationIp|cidr:
      - '10.0.0.0/8'
      - '172.16.0.0/12'
      - '192.168.0.0/16'
      - '127.0.0.0/8'
  condition: selection and not filter_internal
falsepositives:
  - Internal admin scripts and update mechanisms; correlate with parent process and destination reputation
level: medium
tags:
  - attack.command_and_control
  - attack.t1071.001
  - attack.discovery
  - attack.t1016
KQL — Microsoft Sentinel / Defender
// Casbaneiro campaign hunt: HTA->AutoIt chain, geofence/C2 traffic, and OTX hash matches
let CasbHashes = dynamic([
  "4302586202234cdf1ca058fd3c62be0050c8155ed113f3f62337d756e6915044",
  "47d321c1a232e5cdd1e39a06dadbd79114dc1a2f0f8eac289e6b653a5d126f95",
  "51503ce1373c7fa72a1da5c5c4b30f88c8224686669ba4b64196591414fdc64c",
  "5a76669ec410d0b3e21112a4a6fd3207976b299ee27c5fc3d42f2673170ab95e",
  "62ef39ec29966d71c8254f68bd5e320cf24a042d76c12dbafdcc0766861827c5",
  "6bb4372d0d02ec87b76409f69d445a93910964f8db457bafafb97a011da59e73",
  "6e6bd2f7566ffa52d52fa9d5f048bbb9246d3d50110c6b0c248919ad796c6fd4",
  "711c0aa8cde078aa349fb329e3e44e4272ea66a5e651ad8a64893c76a725c859"
]);
// Stage 1: File-level hits on known campaign artifacts
let HashHits = DeviceFileEvents
| where TimeGenerated > ago(30d)
| where SHA256 in (CasbHashes)
| project HashHitTime=TimeGenerated, DeviceName, FileName, FolderPath, SHA256;
// Stage 2: Behavioral chain — mshta.exe spawning script/loader children
let LoaderChain = DeviceProcessEvents
| where TimeGenerated > ago(30d)
| where InitiatingProcessFileName =~ "mshta.exe"
| where FileName in~ ("powershell.exe","cmd.exe","wscript.exe","cscript.exe","rundll32.exe","AutoIt3.exe","certutil.exe","bitsadmin.exe")
| project ChainTime=TimeGenerated, DeviceName, ChildProcess=FileName, ProcessCommandLine, InitiatingProcessCommandLine, AccountName;
// Stage 3: AutoIt from user-writable paths + outbound C2 from script interpreters
let AutoItExec = DeviceProcessEvents
| where TimeGenerated > ago(30d)
| where FileName =~ "AutoIt3.exe"
| where ProcessCommandLine has_any ("\\AppData\\","\\Temp\\","\\ProgramData\\","\\Users\\Public\\")
| project AutoItTime=TimeGenerated, DeviceName, ProcessCommandLine, AccountName;
let ScriptC2 = DeviceNetworkEvents
| where TimeGenerated > ago(30d)
| where InitiatingProcessFileName in~ ("mshta.exe","AutoIt3.exe","wscript.exe","cscript.exe")
| where RemotePort in (80,443,8080)
| where not(RemoteIP startswith "10." or RemoteIP startswith "192.168." or (RemoteIP startswith "172." and toint(split(RemoteIP,".")[1]) between (16..31)))
| project C2Time=TimeGenerated, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteIP, RemoteUrl, RemotePort;
HashHits
| union LoaderChain, AutoItExec, ScriptC2
| sort by DeviceName asc
PowerShell
# Casbaneiro (Metamorfo/Ousaban) Host Hunt — Security Arsenal
# Run elevated. Checks hashes, persistence, staging dirs, and live C2 connections.

$ErrorActionPreference = 'SilentlyContinue'
$casbHashes = @(
  '4302586202234cdf1ca058fd3c62be0050c8155ed113f3f62337d756e6915044',
  '47d321c1a232e5cdd1e39a06dadbd79114dc1a2f0f8eac289e6b653a5d126f95',
  '51503ce1373c7fa72a1da5c5c4b30f88c8224686669ba4b64196591414fdc64c',
  '5a76669ec410d0b3e21112a4a6fd3207976b299ee27c5fc3d42f2673170ab95e',
  '62ef39ec29966d71c8254f68bd5e320cf24a042d76c12dbafdcc0766861827c5',
  '6bb4372d0d02ec87b76409f69d445a93910964f8db457bafafb97a011da59e73',
  '6e6bd2f7566ffa52d52fa9d5f048bbb9246d3d50110c6b0c248919ad796c6fd4',
  '711c0aa8cde078aa349fb329e3e44e4272ea66a5e651ad8a64893c76a725c859'
)

Write-Host "=== [1] Hash sweep in common staging directories ===" -ForegroundColor Cyan
$stagingPaths = @("$env:TEMP","$env:APPDATA","$env:LOCALAPPDATA","$env:ProgramData","C:\Users\Public","$env:USERPROFILE\Downloads")
foreach ($p in $stagingPaths) {
  Get-ChildItem -Path $p -Recurse -File -ErrorAction SilentlyContinue | ForEach-Object {
    $h = (Get-FileHash $_.FullName -Algorithm SHA256).Hash.ToLower()
    if ($casbHashes -contains $h) {
      Write-Host "[HIT] $($_.FullName)  SHA256=$h" -ForegroundColor Red
    }
  }
}

Write-Host "=== [2] Suspicious HTA / AutoIt artifacts on disk ===" -ForegroundColor Cyan
foreach ($p in $stagingPaths) {
  Get-ChildItem -Path $p -Recurse -Include *.hta,*.a3x,*.au3 -File -ErrorAction SilentlyContinue |
    Where-Object { $_.LastWriteTime -gt (Get-Date).AddDays(-60) } |
    ForEach-Object { Write-Host "[ARTIFACT] $($_.FullName)  LastWrite=$($_.LastWriteTime)" -ForegroundColor Yellow }
}
# Invoice/legal-lure PDFs dropped in last 60 days (campaign lure naming)
Get-ChildItem -Path "$env:USERPROFILE\Downloads","$env:TEMP" -Recurse -Include *.pdf -File -ErrorAction SilentlyContinue |
  Where-Object { $_.Name -match '(factura|invoice|notificacion|legal|aviso|cobro|deuda)' -and $_.LastWriteTime -gt (Get-Date).AddDays(-60) } |
  ForEach-Object { Write-Host "[LURE-PDF] $($_.FullName)" -ForegroundColor Yellow }

Write-Host "=== [3] Persistence: Run keys referencing HTA/AutoIt/script paths ===" -ForegroundColor Cyan
$runKeys = @('HKCU:\Software\Microsoft\Windows\CurrentVersion\Run',
             'HKLM:\Software\Microsoft\Windows\CurrentVersion\Run',
             'HKCU:\Software\Microsoft\Windows\CurrentVersion\RunOnce',
             'HKLM:\Software\Microsoft\Windows\CurrentVersion\RunOnce')
foreach ($k in $runKeys) {
  Get-ItemProperty -Path $k | ForEach-Object {
    $_.PSObject.Properties | Where-Object { $_.Value -match '(mshta|AutoIt3|\.hta|\.a3x|wscript|cscript|AppData|ProgramData)' } |
      ForEach-Object { Write-Host "[PERSIST] $k :: $($_.Name) = $($_.Value)" -ForegroundColor Red }
  }
}

Write-Host "=== [4] Scheduled tasks invoking script interpreters ===" -ForegroundColor Cyan
Get-ScheduledTask | ForEach-Object {
  $actions = $_.Actions | Out-String
  if ($actions -match '(mshta|AutoIt3|wscript|cscript|powershell.*-enc)') {
    Write-Host "[TASK] $($_.TaskName) :: $actions" -ForegroundColor Yellow
  }
}

Write-Host "=== [5] Live outbound connections from script interpreters (distributed C2 check) ===" -ForegroundColor Cyan
Get-NetTCPConnection -State Established | ForEach-Object {
  $proc = Get-Process -Id $_.OwningProcess
  if ($proc.ProcessName -match '^(mshta|AutoIt3|wscript|cscript)$') {
    Write-Host "[C2?] $($proc.ProcessName) (PID $($proc.Id)) -> $($_.RemoteAddress):$($_.RemotePort)" -ForegroundColor Red
  }
}

Write-Host "=== Hunt complete. Escalate any [HIT]/[PERSIST]/[C2?] findings to IR immediately. ===" -ForegroundColor Cyan

Response Priorities

Immediate (0–4 hours)

  • Push all 25 SHA-256 IOCs to EDR blocklists and email-gateway sandbox verdicts; block .hta attachments and HTML-application MIME types at the mail perimeter.
  • Deploy the Sigma and KQL detections above; run the retroactive 30-day hash sweep and the mshta.exe → child-process chain hunt.
  • Restrict AutoIt3.exe execution via AppLocker/WDAC unless an approved business use exists — it is one of the highest-signal chokepoints for this entire malware family.

24 Hours

  • Treat this as a credential-theft incident for any host with a confirmed hit. Force password resets on all accounts used on affected endpoints, prioritizing banking, treasury, ERP, and email credentials.
  • Revoke active sessions and refresh tokens (M365, VPN, banking portals) for impacted users; review MFA logs for anomalous LATAM-region authentications.
  • Notify finance/treasury teams to flag and out-of-band verify any payment-change or wire requests originating from LATAM business units in the last 60 days.

1 Week

  • Harden the phishing vector: detonate PDFs in sandbox before delivery, rewrite URLs through a click-time proxy, and add bannering for external invoice/legal-themed mail.
  • Disable or tightly constrain mshta.exe via Attack Surface Reduction rules (e.g., block Office/script-child process creation) and enforce PowerShell Constrained Language Mode on standard-user workstations.
  • Because the campaign is geofenced, verify egress visibility for LATAM offices and remote users — VPN concentrators and regional breakouts must route DNS and HTTP logs to central SIEM. Deploy egress filtering to alert on first-seen external destinations from script-interpreter processes.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.