Metamorfo

MITRE ATT&CK: S0455 View on attack.mitre.org

Aliases: Casbaneiro, Metamorfo

First seen
2018-04-01 00:00:00
Malware type
trojan
Family
Malware family
Operating systems
windows
Related IoCs
51 (39 malicious)
Last IoC activity
2026-08-26 18:26:10
Profile updated
2026-07-07 14:04:42

Targeted industries: financial-services

Targeted regions: country_code:br country_code:mx

Context

Metamorfo is a Latin-American banking trojan operated by a Brazilian cybercrime group that has been active since at least April 2018. The group focuses on targeting banks and cryptocurrency services in Brazil and Mexico.

Recent IoC activity

39 malicious indicators in Maltiverse are attributed to Metamorfo (S0455). The 20 most recently updated:

TypeIndicatorUpdatedSources
file sample f5c0a71b972a63ce6a5e503a0902c8481f788a580a5cbf2246ee4a163bcd44b2.msi 2026-08-26 2
file sample 0bf0eb3822fb47e07d7beabb6f5f8e8d5c76b94ca70bfe379fe0a8b092c8517f 2026-08-11 3
file sample BOLET0_120923__1_.msi 2026-08-03 1
file sample foto.lnk 2026-07-28 1
file sample a4b5950b7ec48255a991f1dc1d2da432.msi 2026-07-23 1
file sample Anexo - 05116510.lnk 2026-06-29 1
file sample BoIetos da Semana.lnk 2026-06-27 1
file sample Curriculum.lnk 2026-06-20 1
file sample 4ec1c47ada2fd1efe8fd1b3608d6fa4b.msi 2026-06-17 1
URL http://modulowinapp.com/TeamViewer.zip 2026-04-30 1
file sample IM-87678A-1A.msi 2026-04-26 1
file sample BoIetos - 16-11.lnk 2026-04-20 1
file sample f41ac6d123e69a06b591a88c0ee7f1fe.msi 2026-03-20 1
file sample Rastreio SEDEX.zip 2026-01-20 1
file sample 926379547581c21c9a65f6f7f624e301.msi 2026-01-20 1
file sample m.zip 2026-01-04 1
file sample IM-vL5WWvBl.msi 2025-12-06 1
file sample poad2_4QJ_Sl__(31).cmd 2025-11-25 1
URL https://live-mail-acesso.lpages.co/doc1/ 2025-11-20 1
file sample Aplicativo Seguro.msi 2025-10-01 1

Detection coverage

  • 1 YARA rules
  • 815 Sigma rules

Malware & tools used

  • JavaScript (attack-pattern)
  • Software Discovery (attack-pattern)
  • Keylogging (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • Asymmetric Cryptography (attack-pattern)
  • Web Protocols (attack-pattern)
  • Msiexec (attack-pattern)
  • Malicious File (attack-pattern)
  • Dynamic-link Library Injection (attack-pattern)
  • Dead Drop Resolver (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Native API (attack-pattern)
  • DLL (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • System Time Discovery (attack-pattern)
  • Non-Application Layer Protocol (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Indicator Removal (attack-pattern)
  • GUI Input Capture (attack-pattern)
  • Virtualization/Sandbox Evasion (attack-pattern)
  • File Deletion (attack-pattern)
  • Modify Registry (attack-pattern)
  • One-Way Communication (attack-pattern)
  • Automated Collection (attack-pattern)

Detection rules

  • ARKBIRD_SOLG_Malware_Casbaneiro_MSI (yara-rule)

Reports & references

  • advintel.io — Economic Growth Digital Inclusion Specialized Crime Financial Cyber Fraud In Latam (report)
  • botconf.eu — B2019 Soucek Hornak Demystifyingbankingtrojansfromlatinamerica (report)
  • umbrella.cisco.com — Navigating Cybersecurity During A Pandemic Latest Malware And Threat Actors (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Metamorfo (report)
  • Cisco Talos — Metamorfo Brazilian Campaigns (report)
  • twitter.com — 1418706916922986504 (report)
  • github.com — Metamorfo.Md (report)
  • Mandiant — Metamorfo Campaign Targeting Brazilian Users (report)
  • cofense.com — Autohotkey Banking Trojan (report)
  • medium.com — The Avast Abuser Metamorfo Banking Malware Hides By Abusing Avast Executable Ac9B8B392767 (report)
  • ESET — Casbaneiro Trojan Dangerou (report)
  • bitdefender.com — Bitdefender Pr Whitepaper Metamorfo Creat4500 En En Genericuse (report)
  • blog.ensilo.com — Metamorfo Avast Abuser (report)
  • MITRE ATT&CK — S0455 (report)
  • ESET — Casbaneiro Trojan Dangerous Cooking (report)

External references