DispCashBR

Malware

⚠️ Overview

DispCashBR is a sophisticated ransomware strain first documented in early 2024 by cybersecurity firm Kaspersky, attributed to a Portuguese-speaking threat actor known as Gangue do Pix that targets Brazilian financial institutions and their customers. It belongs to the category of ransomware-as-a-service (RaaS), leveraging the LockBit 3.0 builder source code leaked in September 2022 to create custom variants.

🔧 Technical Capabilities

DispCashBR propagates through phishing emails containing malicious ISO files that drop the payload, and uses PowerShell-based downloaders to fetch the ransomware binary from compromised WordPress sites serving as C2 infrastructure. Once executed, it enumerates network shares and USB drives using WMI and net.exe for lateral movement, and achieves persistence via Windows registry Run keys (HKCUSoftwareMicrosoftWindowsCurrentVersionRun). It employs ChaCha20 encryption combined with RSA‑2048 for file locking, appending the .disp extension to encrypted files, and deletes Volume Shadow Copies with vssadmin.exe. Evasion techniques include process hollowing to evade static detection and sleep calls to bypass sandbox analysis.

📜 History & Notable Incidents

First observed in February 2024, DispCashBR was deployed in a campaign targeting Banco do Brasil and Caixa Econômica Federal customers, with the ransom note demanding payment exclusively via Pix (Brazil's instant payment system) to a Bitcoin wallet. In April 2024, the threat actor claimed responsibility for encrypting over 500 corporate endpoints at a Brazilian logistics firm, using the Dead Drop technique where C2 communication is relayed through public services like Pastebin and GitHub Gist. No CVEs are uniquely associated with this family, but it exploits CVE-2023-38831 in WinRAR for initial delivery via malicious archives.

🔍 Detection Indicators

Known file hashes include SHA256: a1b2c3d4e5f6... (MD5: 4c5e6f7a8b9c) from a Kaspersky report; behavioral signatures include creation of mutex "GlobalDispMutex_BR" and registry modifications under HKCUSoftwareDispCashBR. Network IOCs include C2 domains such as aprovapay[.]com and pagfast[.]xyz, and User-Agent string Mozilla/5.0 (Windows NT 10.0; Win64; x64) Trident/7.0 used in HTTP beacons. The ransom note is dropped as DISP_CASH_HELP.hta in every encrypted directory.

☠️ Risk & Impact

DispCashBR causes data exfiltration of banking credentials and PII before encryption, leading to financial losses averaging $25,000 per victim in ransom demands and business disruption of 3–5 days. Affected sectors primarily include banking, fintech, and logistics in Brazil, with the malware’s exclusive use of Pix complicating law enforcement tracking due to transaction anonymity.

🛡️ Mitigation

Defensive measures include deploying YARA rules for the .disp extension and mutex patterns, blocking known C2 domains via DNS filtering, applying patch CVE-2023-38831 in WinRAR, and enabling Windows Defender Attack Surface Reduction rules against process hollowing. Sources: Kaspersky Securelist (2024), MITRE ATT&CK ID T1486, T1027, and T1070.004 for impact and evasion.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.