Skip to main content
Mallory
Financially Motivated🇧🇷 BR1 malware family

PLUMP SPIDER

Also known asPLUMP SPIDER

Plump Spider is a financially motivated threat group associated with campaigns targeting Latin America, particularly Brazil. CrowdStrike identified Plump Spider as one of six major financially motivated operators either based in Latin America or primarily focused on targets in the region. Supporting content states the group has a history of financially motivated campaigns abusing government-themed domains and fake .gov.br structures to target Brazilian victims. In the referenced investigation, infrastructure overlap, hosting patterns, and recurring TTPs were assessed as a strong indicator of an operational link between a Brazilian infostealer campaign and Plump Spider. That campaign abused a legitimate Goiás government subdomain and a fake Amapá-themed URL path to distribute a Delphi-based executable, Certificado_PCAP.exe, packaged with Inno Setup. The malware chain established persistence, stole browser credentials, cookies, and session tokens, logged keystrokes, monitored user activity, and communicated with command-and-control infrastructure over HTTPS while disabling certificate validation. A secondary Electron-based component disguised as Boost Note used polling-based tasking, victim ID generation, POST-based exfiltration, and persistence via Windows Run keys and Electron login item settings. The same campaign also involved publicly accessible malicious JavaScript web stealers hosted on related infrastructure. These scripts exfiltrated URLs, cookies, form contents, localStorage, and sessionStorage, dynamically loaded additional payloads, and in one case implemented a full man-in-the-browser attack against Credifit administrative systems by intercepting traffic to admin.credifit.com.br and related APIs while exfiltrating captured data to attacker-controlled endpoints. Investigators also identified attacker infrastructure including kapa.is, kak.is, Webhook.site, and an exposed "Forever v1.0" administrative panel used to manage infected clients and push tasks. Part of the infrastructure was allocated to Master da Web Datacenter, a Brazilian hosting provider previously identified in campaigns attributed to Plump Spider, specifically hosting fake pages in the name of Autbank. Plump Spider is also mentioned alongside other sophisticated eCrime groups observed leveraging advanced social engineering tactics.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Financial Services
  • Software & Services

Where they target

Geographies tied to known operations.

  • 🇧🇷 Brazil

Where they're from

Attributed origin per open-source reporting.

  • BR
MITRE ATT&CK

Tradecraft

2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

2 of 15 tactics3 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0042
Resource Development
1 technique
T1584
Compromise Infrastructure
T1584.004
Server
TA0001
Initial Access
1 technique
T1566
Phishing
IOCS

Observables

50 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping2

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal1

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables50

Domains, IPs, and hashes tied to this actor, refreshed continuously.