Casbaneiro Phishing Targets Latin America and Europe Using Dynamic PDF Lures
Spanish-speaking employees at Latin American and European firms are the target of a multifaceted phishing effort that uses Horabot, another malware, to spread Windows banking trojans like Casbaneiro (also known as Metamorfo).
A Brazilian cybercrime threat actor known as Augmented Marauder and Water Saci has been linked to the behavior. Trend Micro first recorded the e-crime organization in October 2025.
According to a technical analysis released on Tuesday by BlueVoyant security experts Thomas Elkins and Joshua Green, this threat organization uses a broader attack strategy centered on a customized delivery and propagation method that combines WhatsApp, ClickFix tactics, and email-centric phishing.
It is now clear that these Brazil-based operators maintain and use a sophisticated ...

