Talos observed a new campaign specific to South America, namely Brazil. This campaign was focused on various South American banks in an attempt to steal credentials from the user to allow for illicit financial gain for the malicious actors. The campaign Talos analysed focused on Brazilian users and also attempted to remain stealthy by using multiple methods of re-direction. It also used multiple anti-analysis techniques and the final payload was written in Delphi which is quite unique to the banking trojan landscape. The malware is working in the C:UsersPublicAdministrator directory.”]
Source: https://blog.talosintelligence.com/2017/09/brazilbanking.html