Metamorfo

S0455

Malware.View on attack.mitre.org

About this malware

Metamorfo is a Latin-American banking trojan operated by a Brazilian cybercrime group that has been active since at least April 2018. The group focuses on targeting banks and cryptocurrency services in Brazil and Mexico.

Techniques used46

Procedure examples46

TechniqueProcedure example
T1010
Application Window Discovery

Metamorfo can enumerate all windows on the victim’s machine.

T1027.002
Software Packing

Metamorfo has used VMProtect to pack and protect files.

T1027.013
Encrypted/Encoded File

Metamorfo has encrypted payloads and strings.

T1033
System Owner/User Discovery

Metamorfo has collected the username from the victim's machine.

T1036.005
Match Legitimate Resource Name or Location

Metamorfo has disguised an MSI file as the Adobe Acrobat Reader Installer and has masqueraded payloads as OneDrive, WhatsApp, or Spotify, for example.

T1041
Exfiltration Over C2 Channel

Metamorfo can send the data it collects to the C2 server.

T1055.001
Dynamic-link Library Injection

Metamorfo has injected a malicious DLL into the Windows Media Player process (wmplayer.exe).

T1056.001
Keylogging

Metamorfo has a command to launch a keylogger and capture keystrokes on the victim’s machine.

T1056.002
GUI Input Capture

Metamorfo has displayed fake forms on top of banking sites to intercept credentials from victims.

T1057
Process Discovery

Metamorfo has performed process name checks and has monitored applications.

T1059.003
Windows Command Shell

Metamorfo has used cmd.exe /c to execute files.

T1059.005
Visual Basic

Metamorfo has used VBS code on victims’ systems.

T1059.007
JavaScript

Metamorfo includes payloads written in JavaScript.

T1070
Indicator Removal

Metamorfo has a command to delete a Registry key it uses, \Software\Microsoft\Internet Explorer\notes.

T1070.004
File Deletion

Metamorfo has deleted itself from the system after execution.

View all 46 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References2

  1. ESET Casbaneiro Oct 2019 Open source
    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.
  2. Medium Metamorfo Apr 2020 Open source
    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.