Colombia: banking and government lead detections
Trellix says banking and finance drove 55.8% of detections in Colombia. PSE and government also appeared among the targets.
Trellix reported that in Colombia, the banking and financial sector accounted for 55.8% of detections over six months, followed by government at 23.1%. The same report warns of attacks against instant payments like PSE, using AI-driven social engineering, keychain trojans and credential phishing. Separate technical analysis of Casbaneiro and ShadowParasite describes active campaigns targeting banks and services in Latin America, with a focus on Colombia.
Trellix reported that in Colombia, the banking and financial sector accounted for 55.8% of detections over a six-month period, followed by government at 23.1%. An independent Colombian outlet added that healthcare represented 6.1% and that PSE became a focal point for fraud and credential theft campaigns over the last half year.
What did Trellix say about detections in Colombia?
Trellix said banking and finance accounted for the largest share of detections over six months, with government in second place. Local coverage echoed the view that attackers are shifting toward instant payment systems and access credentials, with PSE as a central target.
The report cited by Technocio also said threat actors are heavily targeting account-to-account systems and instant payments through AI-driven social engineering, keychain trojans and credential phishing. Minuto60 reported the same trend and added healthcare to the detection map.
What techniques are being used against banking and payments?
The available reports describe campaigns that combine social engineering, credential theft and banking-oriented malware. In Colombia, Trellix mentioned attacks against instant payments such as PSE, while later technical research documented malware and payment fraud with components designed to evade analysis and capture sensitive data.
FortiGuard Labs, in an analysis summarized by SocPrime on Casbaneiro, explained that the trojan uses a multi-stage infection chain with HTA downloaders and AutoIt loaders. It also detailed geofencing to limit delivery to selected regions of Latin America and a distributed C2 infrastructure that deliberately returns HTTP 403 responses.
The same technical report listed concrete indicators of compromise for regional response teams, including the creation of a .Outlook file in %APPDATA%, MD5-named registry keys under HKCU\SOFTWARE, and malformed HTTP traffic without a Host header, with unusually large Content-Length values. It also warned that the malware injects code into legitimate Windows processes such as RegSvcs.exe and mobsync.exe.
What does the ShadowParasite campaign show in Colombia?
Lumu described ShadowParasite as a payment fraud operation focused on LATAM and especially Colombia, with fake utility payment portals and financial institutions placed in search engines to steal payments and credentials. The research identified at least 288 domains and 47 impersonated brands.
The same investigation reconstructed at least seven months of partial activity and linked 51 initial domains and four IP addresses across four autonomous systems. It also found a panel impersonating 15 Colombian financial institutions built on a single codebase.
In that panel, some entities requested six-digit verification codes and card data. In six institutions, the operation also captured facial biometrics through photo and video, pointing to a high level of sophistication in campaigns aimed at Colombia's financial sector.
How does this fit into the regional context?
Infobae reported that the growth of cyberattacks in Latin America includes state-sponsored activity and that the impact reaches both public and private sectors. The outlet also recalled the 2023 attack on IFX Networks, which affected 78 public entities and more than 760 private companies across the region.
That backdrop now sits alongside more focused campaigns against banking, government and instant payments. In Colombia, the overlap of high detections, payment fraud and banking malware leaves a risk map that is no longer limited to a single technique or a single type of victim.
Sources
- Unmasking ShadowParasite: The Invisible Cyber Fraud Operation Targeting Latamlumu.io· Lumu
- Alerta por el crecimiento de ciberataques en América Latinainfobae.com· Infobae
- Colombia registra 1,3 millones de detecciones de ciberamenazas en seis mesesguapacho.com· Technocio
- Casbaneiro Banking Trojan Uses Distributed C2 Serverssocprime.com· SocPrime
- Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websitescybersecuritynews.com· Cybersecurity News
- Alerta roja digital en Colombia: la inteligencia artificial está acelerando el cibercrimenminuto60.com· Minuto60


