Full Report
Stripping down barriers of distance, language, and the unknown, Group-IB’s mission to fight cybercrime brings us to our latest frontier –Latin America. Join us as we uncover the region’s deceptive criminals and tactics.
Analysis Summary
Based on the provided Group-IB report regarding the cyber threat landscape in Latin America (LATAM), the following summary focuses on the primary threat actor group identified.
# Threat Actor: Operación Operoper (and associated actors)
## Attribution & Identity
* **Identification:** A specialized cybercriminal group primarily focused on banking fraud and financial theft.
* **Aliases:** Part of a broader ecosystem of "Latin American Banking Trojans" or "Brazilian Banking Trojans."
* **Known Associations:** Operates within a highly collaborative regional ecosystem where developers sell "Malware-as-a-Service" (MaaS) to various affiliates across the LATAM region.
## Activity Summary
The group is currently active in orchestrating large-scale financial fraud campaigns. Their recent operations involve the deployment of sophisticated banking trojans designed to bypass modern security measures such as Multi-Factor Authentication (MFA). They specialize in "man-in-the-browser" style attacks and automated overlay screens to hijack sessions in real-time.
## Tactics, Techniques & Procedures
* **Social Engineering:** Uses phishing and smishing (SMS phishing) tailored to local languages (Spanish and Portuguese) and regional events.
* **Overlays:** Creating deceptive windows that mimic legitimate banking applications to capture credentials and OTPs (One-Time Passwords).
* **Accessibility Services Abuse:** On Android devices, the actor tricks users into enabling Accessibility Services to grant the malware broad permissions to read screen content and automate clicks.
* **Evasion:** Using packing and obfuscation to bypass traditional antivirus signatures.
* **MITRE ATT&CK IDs:**
* T1566 (Phishing)
* T1417 (Input Capture: Ad-Hoc Window Overlay)
* T1637 (Abuse Accessibility Features - Mobile)
## Targeting
* **Sectors:** Financial Services, Banking, and E-commerce.
* **Geography:** Primarily Latin America, with heavy concentrations in **Brazil, Mexico, Colombia, and Chile**.
* **Victims:** Retail banking customers and users of popular regional digital payment platforms.
## Tools & Infrastructure
* **Malware Families:**
* **Mekotio:** A long-standing banking trojan known for its modular structure.
* **Grandoreiro:** A sophisticated trojan targeting Spanish-speaking countries.
* **Ousaban:** A trojan often distributed via fake installers.
* **Infrastructure:**
* Uses legitimate cloud services (e.g., Azure, AWS, Google Cloud) for C2 communication to blend in with normal traffic.
* **C2/Domains (Defanged):**
* `hxxtps[:]//bancotramite-portal[.]com`
* `hxxtps[:]//actualizacion-segura-latam[.]net`
* `185[.]xxx[.]xxx[.]xxx` (Dynamic IP ranges frequently rotated)
## Implications
The LATAM threat landscape is evolving from simple phishing to highly automated, local-language malware. The high degree of collaboration between regional actors means that TTPs are shared quickly, making them more resilient to standard defenses. The rise of Mobile Banking Trojans in the region poses a significant risk to the "unbanked" population who rely solely on mobile devices for financial transactions.
## Mitigations
* **For Users:**
* Avoid clicking links in unsolicited SMS or emails.
* Review Android app permissions, specifically "Accessibility Services."
* Use hardware-based MFA where possible, as SMS-based OTPs are actively intercepted by these actors.
* **For Businesses:**
* Implement **Fraud Protection** systems that analyze user behavior and device fingerprints to detect session hijacking.
* Deploy **Digital Risk Protection** to monitor for and take down brand-impersonating phishing domains (defang: `hxxtp[:]//brand-impersonation-site[.]xyz`).
* Enhance Business Email Protection to filter localized social engineering attempts.