Augmented Marauder Uses Dual Chains to Spread Casbaneiro Banking Malware

Brazil-based threat actor Augmented Marauder targets Spanish-speaking users in Latin America and Europe with a multi-pronged phishing campaign. It uses dynamic, password-protected PDF lures themed as court summons to trick victims into downloading ZIP archives containing HTA and VBS scripts. These scripts perform environment checks and download AutoIt loaders that decrypt and execute Casbaneiro banking malware and Horabot, which aids propagation. The campaign combines WhatsApp automation to compromise retail and consumer devices with an advanced email-hijacking engine to breach enterprise perimeters. This dual delivery approach bridges consumer and corporate environments, increasing the risk of cross-tier intrusion and lateral movement within organizations.

Part of the PlainSec briefing for 2026-04-02

Sources