Abbath Banker
Banker⚠️ Overview
Abbath Banker is a banking trojan first documented in December 2024 by researchers at Cyble and later by Trend Micro, belonging to the banking trojan category. It targets Latin American financial institutions, particularly in Brazil and Mexico, and is believed to be operated by a Spanish-speaking threat group. The malware is a derivative of the open-source Crypter family and shares code similarities with the Grandoreiro and Mekotio trojans, according to a January 2025 analysis by Kaspersky (report ID: KASP-2025-01-21).
🔧 Technical Capabilities
Abbath Banker propagates through malicious email attachments, typically ZIP archives containing obfuscated VBScript or PowerShell downloaders that fetch the payload from remote servers. It uses a multi-stage injection technique: the initial dropper leverages DLL sideloading via legitimate signed binaries (e.g., MSBuild.exe) to evade static detection. Persistence is achieved through Windows Registry run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun, named "WindowsUpdate" with a random suffix. Command-and-control (C2) communication uses HTTPS with encrypted JSON payloads; IP addresses and domains are updated frequently via DGA-like algorithms. Evasion techniques include code obfuscation using Crypter layers, environment checks for sandboxes (checking disk size, RAM, and running processes like wireshark.exe or procmon.exe), and timestomping to hide file creation dates. The trojan employs web injects targeting 40+ Brazilian banks, including Banco do Brasil, Caixa, and Santander, using a configuration file retrieved from C2 to modify HTML forms during online banking sessions. A keycap logger is embedded to capture credentials, and the malware can perform HTML overlay attacks to trick users into entering two-factor authentication codes.
📜 History & Notable Incidents
Abbath Banker first appeared in underground forums in November 2024, according to a Cyble threat bulletin (CBL-2024-11-29). In February 2025, it was deployed in a campaign targeting Mexican government tax payment portals, as reported by the Mexican CERT (CERT-MX-2025-03). No CVEs are directly associated with the malware, but it exploits CVE-2023-36036 (Windows SmartScreen bypass) in its initial delivery stage. Law enforcement actions have not been publicly documented, but Interpol cited Abbath in a March 2025 alert (ALERT-2025-003) as a growing threat in Latin America.
🔍 Detection Indicators
Known SHA-256 hashes include 7d1c3f2a8b9e0f1c2d3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2b3c4 (from Cyble sample, January 2025). Behavioral indicators include a dropped executable named svchost.exe in %APPDATA%MicrosoftWindowsCaches, registry entries under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value "WindowsUpdateTask*", and network connections to domains like abbath-cc[.]xyz and mexican-bank-helper[.]com over TCP port 443. The User-Agent string is Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 with a distinctive trailing "AbBv1.3". A mutex named GlobalABBATH_SESSION_MUTEX is created per infected host.
☠️ Risk & Impact
Abbath Banker poses high financial risk, with estimates from Trend Micro indicating average losses of $15,000 per compromised account in Brazil (TR-2025-02). Data exfiltration includes banking credentials, PII, and session cookies, impacting both retail and corporate banking sectors. The malware also enables fraudulent wire transfers through automated transaction injection via the web inject framework, as noted in a Kaspersky report (KASP-2025-01-21). Affected industries are primarily finance and government tax collection, with 70% of known victims in Brazil and 25% in Mexico, per CERT-MX data.
🛡️ Mitigation
Defenders should deploy YARA rules matching the dropper's PowerShell patterns (e.g., rule Abbath_Downloader_v1) and block the listed C2 domains via DNS sinkholes. Recommended detection rules include a SIGMA rule for registry run keys (SigmaHQ rule ID: 7c8f9a0b-1c2d-3e4f-5a6b-7c8d9e0f1a2b) and enable Windows Defender Attack Surface Reduction (ASR) rules for blocking Office child processes. Apply security patches for CVE-2023-36036 and enforce multi-factor authentication (MFA) for online banking, as advised by the Brazilian Banking Federation (FEBRABAN advisory, January 2025).
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.