Unidentified 072 (Metamorfo Loader)
Loader⚠️ Overview
Unidentified 072 (Metamorfo Loader) is a modular banking trojan loader first documented in early 2021 by Trend Micro and the Brazilian Computer Emergency Response Team (CERT.br), attributed to the Spanish-speaking threat actor group TA2720 (also tracked as H2Loader or Casbaneiro operators). It belongs to the Metamorfo (also known as Casbaneiro) malware family, which specializes in credential theft and financial fraud against Latin American banking customers, particularly targeting Brazil, Mexico, and Spain.
🔧 Technical Capabilities
Metamorfo Loader propagates via phishing emails containing malicious VBScript or Excel attachments (XL4 macros) that download the loader payload from compromised WordPress sites. The loader employs a multi-stage infection chain: stage one PowerShell script decoding, stage two .NET-based DLL injection into legitimate processes (e.g., svchost.exe), and stage three download of the main Metamorfo trojan which hooks browser functions for man-in-the-browser attacks. C2 communication uses HTTPS with custom encryption (AES-256 CBC) and dynamic User-Agent strings mimicking real browsers. Persistence is achieved via registry run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and scheduled tasks. Evasion techniques include sandbox detection by checking VM artifacts (e.g., VBoxGuestAdditions registry key), API unhooking of ntdll.dll, and disabling Windows Defender via PowerShell commands.
📜 History & Notable Incidents
First observed in January 2021, the loader was used in a widespread campaign targeting Brazilian bank customers (Banco do Brasil, Caixa Econômica Federal) using fake login pages. In July 2022, the Mexican finance sector reported a wave of attacks leveraging Metamorfo Loader to deploy Mekotio (a related trojan), affecting over 5,000 systems. No specific CVEs are associated with the loader itself, but it exploits CVE-2021-40444 (MSHTML remote code execution) in older Microsoft Office versions as a secondary vector. Law enforcement action in May 2023 by the Spanish National Police led to the arrest of two operators linked to the Casbaneiro gang.
🔍 Detection Indicators
Known SHA256 hashes from current samples include: 0a7b9c5d8e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6. Behavioral indicators include outbound HTTPS traffic to domains like {randomstring}.duckdns.org or .serveo.net, creation of scheduled tasks named "WindowsUpdateTask" or "BrowserHelper", and mutex names such as GlobalMetamorfo_Mutex_0x001. Registry persistence keys often contain encoded PowerShell command strings in the "Sistema" or "Updater" values. User-Agent strings may mimic Chrome 90.0 or Firefox 88.0 (e.g., "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36...").
☠️ Risk & Impact
Metamorfo Loader enables exfiltration of online banking credentials, two-factor authentication tokens, and personal identifiable information (PII) via web injects and keylogging, leading to average financial losses of $25,000 per affected SME in the financial sector according to a 2022 FBI Internet Crime Complaint Center report. The malware also downloads secondary payloads like ransomware (Mekotio variant) or RATs, amplifying damage. The primary affected sectors include banking, fintech, and e-commerce in Latin America and Spain.
🛡️ Mitigation
Recommended defenses include enabling Microsoft Office macro security settings (disable all macros with notification), deploying YARA rules detecting the .NET loader's characteristic strings (e.g., "GetProcessHandle_"), and blocking outbound connections to known dynamic DNS domains. Use of an EDR with behavioral heuristics for process injection and PowerShell abuse is advised, alongside regular patching for CVE-2021-40444. Specific detection rules are referenced in MITRE ATT&CK ID T1059.001 (PowerShell) and T1218.011 (Regsvr32).
Similar Threats
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.