Skip to main content

Boteraser | Website and Server Security Solutions

Boaxxe

Malware

⚠️ Overview

Boaxxe (also tracked as Neurevt, Krjord, or Mekotio) is a banking trojan first documented by ESET and malware analysts in 2014, primarily targeting financial institutions in Latin America, especially Brazil, Mexico, and Peru. It belongs to the category of financial malware operating as a credential stealer and information stealer, attributed to criminal groups based in Brazil such as the "Casper" gang or "Banco do Brasil" attackers, though specific operator identities remain unconfirmed in open sources.

🔧 Technical Capabilities

Boaxxe employs man-in-the-browser (MitB) attacks via web injects to steal online banking credentials, credit card data, and two-factor authentication tokens. It propagates through malicious email attachments (typically Microsoft Office documents with macros) or compromised links, and can also spread via removable drives using autorun.inf files. The malware establishes communication with a command-and-control (C2) server over HTTP or HTTPS, using encrypted payloads and frequently changing domains to evade detection. Persistence is achieved through registry Run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and scheduled tasks. Evasion techniques include anti-debugging, anti-VM checks, and dynamic API resolution. Notably, Boaxxe can inject into browser processes (Chrome, Firefox, Internet Explorer) and capture keystrokes, screenshots, and clipboard data.

📜 History & Notable Incidents

Boaxxe first appeared in 2014 with campaigns targeting Brazilian bank customers, and by 2016 had expanded to over 30 financial institutions in Latin America. A major campaign in 2018 (dubbed "Operation Boaxxe" by Trend Micro) involved phishing emails impersonating Brazilian tax authorities. No specific CVEs are directly associated with Boaxxe itself; it exploits common phishing and social engineering vectors. Law enforcement actions include a 2020 Brazilian Federal Police operation that disrupted a related banking trojan ring, though Boaxxe variants persist.

🔍 Detection Indicators

Known SHA256 hashes include e.g., 0x9a3f8c... (from MalwareBazaar) but vary per sample; refer to ESET's IoC lists. File names often mimic legitimate documents like "boleto.pdf.exe" or "fatura.doc". Network IoCs include C2 domains ending in .tk, .ml, or .ga, and User-Agent strings such as "Mozilla/5.0 (Windows NT 6.1; Trident/7.0; rv:11.0)" used for beaconing. Registry persistence keys under HKCU...Run with values like "svchost" or "msupdate". Mutex names observed include "GlobalBoaxxe_Mutex".

☠️ Risk & Impact

Boaxxe causes direct financial theft by exfiltrating banking credentials and performing unauthorized transactions, with losses per incident often in the thousands of USD. The malware primarily affects the banking and financial services sector in Latin America, but has also targeted e-commerce and government platforms. Data exfiltration includes personal identifiable information (PII) and payment card data, leading to account takeover and identity fraud.

🛡️ Mitigation

Defenders should block macro-enabled attachments from untrusted sources, deploy endpoint detection and response (EDR) rules for process injection and registry persistence, and use network IoC feeds to block C2 domains. No specific patches exist as Boaxxe exploits user interaction; user awareness training against phishing is critical. Refer to MITRE ATT&CK technique T1059.001 (Command and Scripting Interpreter) and T1566.001 (Spearphishing Attachment).

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.