{
  "id": 7289728,
  "title": "Casbaneiro distributes command traffic across multiple servers",
  "url": "https://urgent.news/2026/09/14/casbaneiro-distributes-command-traffic-across-multiple-servers",
  "topic": "world",
  "section": "World",
  "published": "2026-09-14T07:55:58.000Z",
  "source": {
    "name": "Arabian Post",
    "slug": "arabian-post",
    "url": "https://thearabianpost.com/casbaneiro-distributes-command-traffic-across-multiple-servers/"
  },
  "original_language": "en",
  "account": "A recent Casbaneiro banking Trojan campaign, targeting users in Latin America, utilizes geofenced phishing, staged malware delivery, and separate command-and-control servers to evade detection, according to security research. The campaign, observed in August, primarily affected Argentina, Peru, Colombia, and Mexico. Phishing emails and PDF documents, disguised as invoices, legal notices, or court-related communications, were used to trick victims into following embedded links. The infection process begins when a user clicks a link, leading to a webpage that checks their IP address. If the user is in the targeted region, they receive a webpage containing a Base64-encoded ZIP archive embedded in JavaScript. This archive holds an HTA file that retrieves an XML-based script package, which performs environment checks before proceeding. The malware downloads three components separately to avoid detection: a legitimate AutoIt interpreter, a compiled AutoIt script, and a compressed file with the final payload. The loader then establishes persistence and injects the payload into the RegSvcs.exe or mobsync.exe process. Casbaneiro gathers email addresses and Outlook data before sending it to attacker-controlled servers. The malware's control traffic is divided among different servers based on the victim's location and bank association, making it harder for defenders to detect and analyze the malicious activity.",
  "summary": "A Casbaneiro banking Trojan campaign targeting users in Latin America is using geofenced phishing, staged malware delivery and separate command-and-control servers to make malicious activity harder to detect and analyse, according to security research published this month. FortiGuard Labs said it observed the campaign in August, with activity focused on Argentina, Peru, Colombia and Mexico.…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}