PULSE NAME
IOC - Unpacking Augmented Marauder’s Multi-Pronged Casbaneiro Campaigns
WHITE celestre 2026-04-03 Modified: 2026-04-03
20
IOCs
MEDIUM VOLUME
BlueVoyant researchers have uncovered a broad, multi-pronged phishing campaign targeting Spanish-speaking users in organizations across Latin America and now Europe as well. While recent industry intelligence heavily documented attacks utilizing WhatsApp to deliver banking trojans under the umbrella of the Brazil-based eCrime group Augmented Marauder (a.k.a. Water Saci), the BlueVoyant Threat Fusion Cell (TFC) identified concurrent, ongoing attack activity showing this threat group employs a wider-ranging attack model focused on a bespoke delivery and propagation mechanism that includes WhatsApp, ClickFix techniques and email-centric phishing. This in-depth analysis shows how Augmented Marauder is simultaneously deploying Horabot to deliver the Casbaneiro (a.k.a. Metamorfo) banking trojan through a comprehensive phishing operation targeting Latin America that has also extended its attacks to users in Spain.
Indicators of Compromise (3 / 20 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 31c7c479b03aef2f5cf4947149d69f52 MD5 of 4e08a1525a62a387595a2e4942b56ec3f3b3259996115ea2e6ea3638ccb87705 2026-04-03
FileHash-MD5 a112765dd04547072d649afe7deeb3b7 MD5 of 1693448804bf1c90ad7317af250bcd6ea021256e33e983b224aea81d4ecc2e20 2026-04-03
FileHash-MD5 aec9ed01b85713acc6a7f1da4d94ee1b MD5 of 1af69a3283e28a8cc9a11819ecc2f2cff46dcabbfa78cefc71a02b881a064593 2026-04-03