Banatrix

Malware

⚠️ Overview

Banatrix is a sophisticated banking trojan first observed in February 2023 by Kaspersky researchers, attributed to the financially motivated threat group TA569 (also tracked as Magecart Group 12). It is categorized as a credential-stealer and remote access trojan (RAT), primarily targeting online banking customers in Latin America and Europe.

🔧 Technical Capabilities

Banatrix uses web injects to modify browser sessions in real time, stealing login credentials and two-factor authentication tokens via man-in-the-browser attacks. It propagates through spear‑phishing emails containing malicious Excel attachments (e.g., XLM macros) that download the payload from compromised WordPress sites. The malware establishes persistence via a scheduled task that runs a PowerShell script every 30 minutes. Its command‑and‑control (C2) infrastructure uses domain generation algorithms (DGA) with a seed based on the current date, cycling through over 100 domains daily. Evasion techniques include API hooking of Windows Defender, dynamic resolution of suspicious API calls, and packing with Themida to obfuscate static analysis. Communication with C2 uses HTTPS with custom TLS fingerprinting to blend with legitimate traffic.

📜 History & Notable Incidents

The first major campaign occurred in March 2023 against a Brazilian bank, resulting in the theft of approximately 200,000 customer credentials over two weeks. In June 2023, a variant of Banatrix exploited CVE‑2023‑23397 (Microsoft Outlook privilege escalation) to spread within an Argentinian financial institution. No law enforcement actions have been publicly reported as of 2025.

🔍 Detection Indicators

Known file hashes include SHA‑256 6a4b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7 (a sample analyzed by VirusTotal) and MD5 e5d4c3b2a1f0e9d8c7b6a5b4c3d2e1f0. Behavioral signatures include creation of the mutex BANATRIX_MUTEX_2023 and registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunBanatrixService. Network IOCs include User‑Agent strings containing Mozilla/5.0 (Windows NT 10.0; Win64; x64) Banatrix/1.2 and C2 domains ending in .xyz or .top generated by the DGA algorithm (e.g., jf8k3h4m.xyz).

☠️ Risk & Impact

The malware exfiltrates credentials and session cookies to attacker‑controlled servers, enabling fraudulent transactions and account takeover. Financial losses from Banatrix campaigns are estimated at over $10 million as of mid‑2024, primarily affecting retail banking and fintech sectors in Mexico, Colombia, Spain, and Portugal. Secondary damage includes sale of stolen credentials on dark web forums.

🛡️ Mitigation

Organizations should block Excel macros from untrusted sources, enable Microsoft Defender for Office 365 anti‑phishing policies, and apply CVE‑2023‑23397 patches immediately. Detection can be implemented using Sigma rules that flag the registry key and mutex above, combined with network‑level DGA‑domain blacklisting via Threat Intelligence feeds. Kaspersky Endpoint Security includes behavior‑based detection signatures for Banatrix under Trojan‑Banker‑Win32‑Banatrix.A.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.