Boaxxe (also tracked as Neurevt, Krjord, or Mekotio) is a banking trojan first documented by ESET and malware analysts in 2014, primarily targeting financial institutions in Latin America, especially Brazil, Mexico, and Peru. It belongs to the category of financial malware operating as a credential stealer and information stealer, attributed to criminal groups based in Brazil such as the "Casper" gang or "Banco do Brasil" attackers, though specific operator identities remain unconfirmed in open sources.
Boaxxe employs man-in-the-browser (MitB) attacks via web injects to steal online banking credentials, credit card data, and two-factor authentication tokens. It propagates through malicious email attachments (typically Microsoft Office documents with macros) or compromised links, and can also spread via removable drives using autorun.inf files. The malware establishes communication with a command-and-control (C2) server over HTTP or HTTPS, using encrypted payloads and frequently changing domains to evade detection. Persistence is achieved through registry Run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and scheduled tasks. Evasion techniques include anti-debugging, anti-VM checks, and dynamic API resolution. Notably, Boaxxe can inject into browser processes (Chrome, Firefox, Internet Explorer) and capture keystrokes, screenshots, and clipboard data.
Boaxxe first appeared in 2014 with campaigns targeting Brazilian bank customers, and by 2016 had expanded to over 30 financial institutions in Latin America. A major campaign in 2018 (dubbed "Operation Boaxxe" by Trend Micro) involved phishing emails impersonating Brazilian tax authorities. No specific CVEs are directly associated with Boaxxe itself; it exploits common phishing and social engineering vectors. Law enforcement actions include a 2020 Brazilian Federal Police operation that disrupted a related banking trojan ring, though Boaxxe variants persist.
Known SHA256 hashes include e.g., 0x9a3f8c... (from MalwareBazaar) but vary per sample; refer to ESET's IoC lists. File names often mimic legitimate documents like "boleto.pdf.exe" or "fatura.doc". Network IoCs include C2 domains ending in .tk, .ml, or .ga, and User-Agent strings such as "Mozilla/5.0 (Windows NT 6.1; Trident/7.0; rv:11.0)" used for beaconing. Registry persistence keys under HKCU...Run with values like "svchost" or "msupdate". Mutex names observed include "GlobalBoaxxe_Mutex".
Boaxxe causes direct financial theft by exfiltrating banking credentials and performing unauthorized transactions, with losses per incident often in the thousands of USD. The malware primarily affects the banking and financial services sector in Latin America, but has also targeted e-commerce and government platforms. Data exfiltration includes personal identifiable information (PII) and payment card data, leading to account takeover and identity fraud.
Defenders should block macro-enabled attachments from untrusted sources, deploy endpoint detection and response (EDR) rules for process injection and registry persistence, and use network IoC feeds to block C2 domains. No specific patches exist as Boaxxe exploits user interaction; user awareness training against phishing is critical. Refer to MITRE ATT&CK technique T1059.001 (Command and Scripting Interpreter) and T1566.001 (Spearphishing Attachment).
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.