PLUMP SPIDER
Plump Spider is a financially motivated threat group associated with campaigns targeting Latin America, particularly Brazil. CrowdStrike identified Plump Spider as one of six major financially motivated operators either based in Latin America or primarily focused on targets in the region. Supporting content states the group has a history of financially motivated campaigns abusing government-themed domains and fake .gov.br structures to target Brazilian victims. In the referenced investigation, infrastructure overlap, hosting patterns, and recurring TTPs were assessed as a strong indicator of an operational link between a Brazilian infostealer campaign and Plump Spider. That campaign abused a legitimate Goiás government subdomain and a fake Amapá-themed URL path to distribute a Delphi-based executable, Certificado_PCAP.exe, packaged with Inno Setup. The malware chain established persistence, stole browser credentials, cookies, and session tokens, logged keystrokes, monitored user activity, and communicated with command-and-control infrastructure over HTTPS while disabling certificate validation. A secondary Electron-based component disguised as Boost Note used polling-based tasking, victim ID generation, POST-based exfiltration, and persistence via Windows Run keys and Electron login item settings. The same campaign also involved publicly accessible malicious JavaScript web stealers hosted on related infrastructure. These scripts exfiltrated URLs, cookies, form contents, localStorage, and sessionStorage, dynamically loaded additional payloads, and in one case implemented a full man-in-the-browser attack against Credifit administrative systems by intercepting traffic to admin.credifit.com.br and related APIs while exfiltrating captured data to attacker-controlled endpoints. Investigators also identified attacker infrastructure including kapa.is, kak.is, Webhook.site, and an exposed "Forever v1.0" administrative panel used to manage infected clients and push tasks. Part of the infrastructure was allocated to Master da Web Datacenter, a Brazilian hosting provider previously identified in campaigns attributed to Plump Spider, specifically hosting fake pages in the name of Autbank. Plump Spider is also mentioned alongside other sophisticated eCrime groups observed leveraging advanced social engineering tactics.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Financial Services
- Software & Services
Where they target
Geographies tied to known operations.
- 🇧🇷 Brazil
Where they're from
Attributed origin per open-source reporting.
- BR
Tradecraft
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
1 malware family attributed to this actor across reporting.
Observables
50 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financial fraud activity targeting the Brazilian public, characterized by abuse of legitimate government domains and spoofed .gov.br-style infrastructure to distribute stealers, hijack sessions, and increase victim trust. The report assesses the current campaign as operationally linked to this group through infrastructure overlap and continuity of TTPs.
Financially motivated criminal activity cluster identified as a major operator in Latin America; described as based in LATAM or primarily focused on targets in the region.
eCrime group cited as leveraging AI-enabled social engineering (notably vishing/impersonation) to steal credentials and bypass controls.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.