← Back to Feed

Casbaneiro: A Banking Trojan with Distributed Data-Receiving Servers

September 10, 2026 · Fortinet Threat Research · Severity: MEDIUM

FortiGuard Labs has analyzed a new Casbaneiro campaign targeting Latin America that uses geofencing and distributed data-receiving servers to evade analysis and detection. The banking Trojan employs geographic restrictions to limit analysis by security researchers, only activating on systems within target regions. By distributing its command infrastructure across multiple servers, Casbaneiro increases resilience against takedown efforts and complicates network-based detection.

FortiGuard Labs examines how a new Casbaneiro campaign targeting Latin America uses geofencing and distributed servers to evade analysis and detection

      

Key Takeaways

  • A new Casbaneiro banking Trojan campaign is targeting Latin America using geofencing to restrict activation to specific geographic regions and evade security analysis.
  • The malware employs distributed data-receiving servers across multiple infrastructure points, increasing resilience against takedown and complicating detection.
  • Geofencing techniques allow the Trojan to avoid triggering in sandbox environments outside target regions, making traditional automated analysis less effective.
☕ Buy a Coffee