{
  "family": "bancobras",
  "sample_count": 1,
  "category": "trojan",
  "description": "<h3>Executive Summary</h3>\nBancobras (short for Banco Brasil) is a highly specialized family of Banking Trojans explicitly engineered to target the customers of major Brazilian financial institutions. Operating as a severe regional threat, Bancobras utilizes sophisticated overlay attacks and keystroke logging to bypass local security controls, aiming to initiate fraudulent wire transfers and completely drain the victim's bank accounts.\n\n<h3>Infection Vector and Technical Capabilities</h3>\nBancobras is predominantly distributed via hyper-localized phishing campaigns (malspam) written in fluent Portuguese, often masquerading as urgent tax documents (Boleto), traffic fines, or fake security updates from Brazilian telecom providers.\n\nOnce executed, the trojan establishes persistence and monitors the user's activity for financial triggers:\n<ul>\n<li><strong>Targeted Browser Monitoring:</strong> Bancobras constantly monitors the active window title and the browser's address bar. It contains a hardcoded list of URLs corresponding to major Brazilian banks (e.g., Banco do Brasil, Itaú, Caixa Econômica Federal).</li>\n<li><strong>Overlay Attacks (Screen Hijacking):</strong> When the user attempts to log into a targeted bank, Bancobras deploys its primary weapon: a full-screen, uncloseable overlay graphic that perfectly mimics the bank's legitimate login portal. The user is tricked into typing their agency number, account number, and password directly into the malware's interface.</li>\n<li><strong>Bypassing Local Security (Trusteer/Warsaw):</strong> Brazilian banks heavily utilize local security software (like Warsaw or Trusteer). Bancobras variants frequently contain specific routines designed to blind, disable, or bypass these specific security modules before initiating the overlay attack.</li>\n</ul>\n\n<h3>Threat Assessment</h3>\nA Bancobras infection is a critical security incident that almost invariably leads to immediate financial loss. The trojan's ability to spoof legitimate banking portals makes it incredibly difficult for standard users to detect the ongoing theft.\n\n<h3>Incident Response and Remediation</h3>\n<ul>\n<li><strong>Immediate Account Freeze:</strong> The victim must contact their financial institution immediately using a known-clean device (like a mobile phone) to freeze their accounts and halt any pending fraudulent transfers.</li>\n<li><strong>Endpoint Eradication (Safe Mode):</strong> Because Bancobras deeply hooks into the operating system to maintain its overlays and disable local security tools, the infected machine must be booted into Windows Safe Mode to properly execute an enterprise anti-malware scan and remove the trojan executables.</li>\n<li><strong>Password Reset:</strong> All credentials entered on the machine, specifically banking passwords, must be changed.</li>\n</ul>",
  "cta": "Published by the SystemHelpdesk team.",
  "aliases": [
    "Trojan-Banker.Bancobras",
    "Banker.Braz",
    "Win32/Bancobras"
  ],
  "enrichment_level": "insufficient_information",
  "faq": [],
  "faq_count": 0,
  "mitre_attack": [
    "T1056.002",
    "T1185",
    "T1566.001",
    "T1562.001"
  ],
  "cisa_advisory": null,
  "last_updated": "2026-07-01T17:06:28Z",
  "type": "Banking Trojan",
  "target_industries": [
    "Global / Opportunistic"
  ],
  "motivation": "Opportunistic",
  "threat_actors": [
    "Unknown / Cybercriminal"
  ],
  "target_geographies": [
    "Global"
  ]
}