Return of Sedinho: Current situation and new tactics of the Brazilian banking trojan ecosystem
During several years we have been tracking the evolution of Brazilian banking trojans, their expansion into countries well beyond their original sphere of influence, and the law enforcement operations that attempted to disrupt their activity. Building on that work, this talk revisits the current landscape and examines the latest improvements and changes introduced by the malware operators behind these groups. In this session, we will analyze several recent financially motivated campaigns that show how Latin American threat actors are not only evolving classic banking malware, but also introducing NFC based mobile fraud against victims in multiple countries. We will provide concrete examples of how well known families such as Grandoreiro and Casbaneiro are refining both their techniques and their social engineering narratives while continuously adapting their malware infection chains and evasion strategies. We will also introduce their newest Android campaigns that leverage NFC fraud through a new NGate variant that masquerades as legitimate applications intended to relay NFC card data between devices. Cybercriminals distribute these trojanized apps under various pretexts, including online banking tools, lottery apps, and shopping applications. Once installed, the malware intercepts NFC payment card data and the victim's PIN, forwarding them to attacker controlled infrastructure to enable contactless ATM cash outs and fraudulent POS transactions, all without requiring additional risky permissions. Throughout the talk, we will walk through the observed tactics, techniques, and procedures, highlighting how the malware code, supporting infrastructure, and social engineering patterns have changed compared to the campaigns we analyzed previously. Our goal is to raise awareness of the ongoing evolution of these Latin American originated malware operations and to equip security teams with the context they need to detect and block these threats before they can cause damage to their organizations.