logo

CPL-Malware-in-Brasil-zx02m.pdf

ID: 4b7b520a-07da-40a5-8026-c84a593b063f

STIX ID: report--4b7b520a-07da-40a5-8026-c84a593b063f

Threat Score

70/100

Uploaded: 2026-08-05

Published Date: 2026-08-05

Last Modified Date: 2026-08-05

Created by: gogogo

TLP:GREEN
...
...
This report analyzes a widespread campaign in Brazil where malicious CPL (Control Panel) files are distributed via phishing (attachments, ZIPs, HTML refresh links and URL shorteners) to act as Trojan Downloaders—primarily Win32/TrojanDownloader.Banload—that retrieve and execute banking trojans to steal credentials. The paper provides technical reversal of CPIApplet payloads, a custom string decryption algorithm (with sample Python), anti-VM checks in DllMain, lists of 419 URLs and ~300 domains (many Brazilian), packer usage, campaign statistics showing large targeting of Brazilian users, and reproduction of propagation emails and IoCs.