Skip to main content
Mallory
MalwareUsed by 2 actors

Mispadu

Mispadu is a Latin American banking trojan, also referred to in the content as Mispadu/URSA, and identified by ESET as one of at least 11 distinct concurrently active LATAM banking malware families. It is associated with financially motivated activity including the Brazil-linked Malteiro cluster, which is described as operating and distributing the Mispadu/URSA banking trojan via a malware-as-a-service model, and with TA2725, which has used Brazilian banking malware including Mispadu to target organizations mainly in Brazil, Mexico, and Spain. Reported targeting also includes campaigns against Mexico and Brazil, and to a lesser extent Spain, Italy, and Portugal. Mispadu checks the compromised system language ID and terminates execution if the system is not configured for Spanish or Portuguese, indicating regional targeting. Infection relies on user execution of malicious files; related campaigns and clusters are described using spearphishing emails, malicious ZIP attachments, HTA attachments, VBS-based droppers, AutoIT loaders, and compressed executables. The malware can steal credentials from Google Chrome, obtain credentials from mail clients via NirSoft MailPassView, monitor browser activity for online banking actions, and display full-screen overlay images to block access to banking sites or solicit additional information. It can also capture and replace Bitcoin wallet data in the clipboard on a compromised host. Mispadu sends collected financial data to its command-and-control server and contains a copy of the OpenSSL library to encrypt C2 traffic. Its binary has been injected into memory via WriteProcessMemory, and related reporting notes injection of the Mispadu DLL into a process. Within the broader LATAM banking trojan ecosystem, Mispadu shares traits such as Delphi-based implementation and use of communication protocols based on the Delphi Remote Access PC component.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Malteiro

Mispadu checks and will terminate execution if the compromised system’s language ID is not Spanish or Portuguese.

via mitre attack websiteattack.mitre.org
TA2725

TA2725 is a threat actor Proofpoint tracked since March 2022 that is known for using Brazilian banking malware (including Mispadu, Astaroth, and historically Grandoreiro) and credential phishing to target organizations mainly in Brazil, Mexico, and Spain.

via proofpoint threat insight blogproofpoint.com
MITRE ATT&CK

Techniques & procedures

29 distinct techniques documented for this family, organized by ATT&CK tactic.

Execution

3 techniques
T1059.005Visual BasicEvidence1
TacticExecution

The content repeatedly describes threat actors and malware using VBScript, VBS, VBA macros, and Visual Basic code for execution, payload delivery, persistence, reconnaissance, and command execution.

T1204User ExecutionEvidence1
TacticExecution

The content repeatedly describes victims being lured into opening malicious attachments, enabling macros, launching installers, clicking embedded files/links, or otherwise directly executing malicious content.

T1204.002Malicious FileEvidence1
TacticExecution

Examples include: "Sandworm Team leveraged Microsoft Office attachments which contained malicious macros..."; "Bumblebee has relied upon a user opening an ISO file to enable execution of malicious shortcut files and DLLs"; "Lumma Stealer has gained initial execution through victims opening malicious executable files embedded in zip archives, and MSI files within RAR files."

Persistence

4 techniques
T1112Modify RegistryEvidence1

Across the content, malware repeatedly 'adds Registry Run keys', 'creates Registry entries', 'modifies the Windows Registry', or 'overwrites registry keys' to maintain persistence.

T1176Software ExtensionsEvidence1

“In Brazil, we have seen it distributing a malicious Google Chrome extension… The extension … is named ‘Securty [sic] System 1.0’…”

T1547.001Registry Run Keys / Startup FolderEvidence3

Multiple entries describe creating .lnk shortcuts in Startup folders, such as BACKSPACE creating a shortcut to itself in the CSIDL_STARTUP directory and DarkGate creating an LNK object in the victim startup folder. | The content repeatedly describes malware and threat actors establishing persistence by adding values under HKCU/HKLM\Software\Microsoft\Windows\CurrentVersion\Run or RunOnce, and by placing executables, scripts, .lnk files, or .bat files in the Windows Startup folder.

T1547.009Shortcut ModificationEvidence1

The content repeatedly notes creation of '.lnk shortcut' files in the Startup folder, such as BACKSPACE creating a shortcut in CSIDL_STARTUP, DarkGate creating an LNK object in the victim startup folder, and Operation Dream Job placing LNK files into victims' startup folder.

T1055Process InjectionEvidence3

The content repeatedly describes adversaries and malware injecting code, shellcode, DLLs, or payloads into legitimate processes such as svchost.exe, explorer.exe, iexplore.exe, wuauclt.exe, lsass.exe, and browser processes.

T1055.001Dynamic-link Library InjectionEvidence1

Malteiro has injected Mispadu’s DLL into a process.

T1547.001Registry Run Keys / Startup FolderEvidence3

Multiple entries describe creating .lnk shortcuts in Startup folders, such as BACKSPACE creating a shortcut to itself in the CSIDL_STARTUP directory and DarkGate creating an LNK object in the victim startup folder. | The content repeatedly describes malware and threat actors establishing persistence by adding values under HKCU/HKLM\Software\Microsoft\Windows\CurrentVersion\Run or RunOnce, and by placing executables, scripts, .lnk files, or .bat files in the Windows Startup folder.

T1547.009Shortcut ModificationEvidence1

The content repeatedly notes creation of '.lnk shortcut' files in the Startup folder, such as BACKSPACE creating a shortcut in CSIDL_STARTUP, DarkGate creating an LNK object in the victim startup folder, and Operation Dream Job placing LNK files into victims' startup folder.

Stealth

6 techniques
T1027Obfuscated Files or InformationEvidence3
TacticStealth

The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.

T1036MasqueradingEvidence1
TacticStealth

“Mispadu masquerades as a discount coupon.”

T1055Process InjectionEvidence3

The content repeatedly describes adversaries and malware injecting code, shellcode, DLLs, or payloads into legitimate processes such as svchost.exe, explorer.exe, iexplore.exe, wuauclt.exe, lsass.exe, and browser processes.

T1055.001Dynamic-link Library InjectionEvidence1

Malteiro has injected Mispadu’s DLL into a process.

T1140Deobfuscate/Decode Files or InformationEvidence3
TacticStealth

The content repeatedly describes malware and threat actors decoding, decrypting, or deobfuscating payloads, strings, configuration data, commands, and C2 traffic prior to execution or use, e.g., 'APT28 macro uses the command certutil -decode to decode contents of a .txt file storing the base64 encoded payload' and 'Action RAT can use Base64 to decode actor-controlled C2 server communications.'

T1218.007MsiexecEvidence1
TacticStealth

“AppleJeus delivered components using a Windows Installer package (.msi)… executed the 3CXDesktopApp.exe…”, “APT38 has used msiexec.exe to execute malicious files.”, “Rancor has used msiexec to download and execute malicious installer files over HTTP.”, “TA505 has used msiexec to download and execute malicious Windows Installer files.”

T1112Modify RegistryEvidence1

Across the content, malware repeatedly 'adds Registry Run keys', 'creates Registry entries', 'modifies the Windows Registry', or 'overwrites registry keys' to maintain persistence.

Credential Access

5 techniques
T1056Input CaptureEvidence2

“Mispadu can monitor browser activity for online banking actions and display full-screen overlay images...”

T1056.003Web Portal CaptureEvidence1

Metamorfo has displayed fake forms on top of banking sites to intercept credentials from victims. Mispadu can monitor browser activity for online banking actions and display full-screen overlay images to block user access to the intended site or present additional data fields.

T1555Credentials from Password StoresEvidence2

Agent Tesla has the ability to steal credentials from FTP clients and wireless profiles... APT33 has used a variety of publicly available tools like LaZagne to gather credentials... Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the credential vault and DPAPI.

T1555.003Credentials from Web BrowsersEvidence3

The content repeatedly describes threat actors and malware stealing usernames, passwords, cookies, session tokens, and other saved credentials from web browsers such as Chrome, Firefox, Internet Explorer, Edge, Opera, Safari, and Yandex.

T1555.005Password ManagersEvidence1

Evilnum can collect email credentials from victims... Malteiro has obtained credentials from mail clients via NirSoft MailPassView... MgBot includes modules for stealing stored credentials from Outlook and Foxmail email client software... PLEAD has the ability to steal saved passwords from Microsoft Outlook.

Discovery

5 techniques
T1057Process DiscoveryEvidence2
TacticDiscovery

The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.

T1082System Information DiscoveryEvidence3
TacticDiscovery

The content repeatedly describes malware and threat actors collecting host details such as OS version, hostname, architecture, CPU, memory, BIOS, domain, language, and other configuration data; e.g., "APT41 uses multiple built-in commands such as systeminfo and net config Workstation to enumerate victim system basic configuration information."

T1083File and Directory DiscoveryEvidence1
TacticDiscovery

“Mispadu searches for various filesystem paths in order to determine what applications are installed…”

T1217Browser Information DiscoveryEvidence1
TacticDiscovery

“...leveraged ICONICSTEALER to steal browser information to include browser history...” / “...collected browser bookmark information...” / “...retrieve browser history...” / “...gather browser data such as bookmarks and visited sites...”

T1614.001System Language DiscoveryEvidence4
TacticDiscovery

Avaddon checks for specific keyboard layouts and OS languages to avoid targeting Commonwealth of Independent States (CIS) entities... Bazar can perform a check to ensure that the operating system's keyboard and language settings are not set to Russian... Clop has checked the keyboard language using the GetKeyboardLayout() function... Ryuk has been observed to query the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\Language and the value InstallLanguage.

Collection

4 techniques
T1056Input CaptureEvidence2

“Mispadu can monitor browser activity for online banking actions and display full-screen overlay images...”

T1056.003Web Portal CaptureEvidence1

Metamorfo has displayed fake forms on top of banking sites to intercept credentials from victims. Mispadu can monitor browser activity for online banking actions and display full-screen overlay images to block user access to the intended site or present additional data fields.

T1113Screen CaptureEvidence1

“For its backdoor functionality, Mispadu can take screenshots…”

T1115Clipboard DataEvidence2

“Mispadu also monitors the content of the clipboard and tries to replace potential bitcoin wallets with its own…”

T1573Encrypted ChannelEvidence1

The content repeatedly describes malware and threat actors using SSL, TLS, HTTPS, RSA, AES, Blowfish, RC4, ECIES, Diffie-Hellman, OpenSSL, WolfSSL, and mutual TLS to protect command and control traffic.

T1573.002Asymmetric CryptographyEvidence1

Multiple malware families and intrusion sets are described as encrypting C2 traffic using SSL/TLS/HTTPS (e.g., "used HTTPS for command and control", "encrypts C2 communications with TLS", "uses SSL for encrypting C2 communications", "TLS-encrypted WebSocket Protocol (WSS) for C2").

Exfiltration

1 technique
T1041Exfiltration Over C2 ChannelEvidence3

ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.

Impact

1 technique
T1657Financial TheftEvidence1
TacticImpact

Malteiro targets organizations in a wide variety of sectors via the use of Mispadu banking trojan with the goal of financial theft.

INDICATORS OF COMPROMISE

IOCs tracked for this family

26 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
5 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
15 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

Other
6 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
hash.sha1●●●●●●●●●●●●View more in app7 years ago
hash.sha1●●●●●●●●●●●●View more in app7 years ago
hash.sha1●●●●●●●●●●●●View more in app7 years ago
hash.sha1●●●●●●●●●●●●View more in app7 years ago
hash.sha1●●●●●●●●●●●●View more in app7 years ago
hash.sha1●●●●●●●●●●●●View more in app7 years ago
ACTIVITY FEED

Recent activity

41 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

the hacker newsNews
Feb 12, 2026
ThreatsDay Bulletin: AI Prompt RCE, Claude 0-Click, RenEngine Loader, Auto 0-Days & 25+ Stories

Banking trojan targeting Latin America (notably Mexico and Brazil) delivered via phishing with HTA attachments (sometimes via password-protected PDFs); uses an AutoIT loader and dynamically generated delivery artifacts to frustrate EDR; includes self-propagation via email and expanded targeting to banks outside LATAM and crypto exchanges.

Read more
the hacker newsNews
Feb 12, 2026
ThreatsDay Bulletin: AI Prompt RCE, Claude 0-Click, RenEngine Loader, Auto 0-Days & 25+ Stories

Banking trojan targeting Latin America (and expanding beyond) delivered via phishing with HTA attachments; uses an AutoIT loader and legitimate files; can self-propagate via email and targets online banking sites and cryptocurrency exchanges.

Read more
proofpoint threat insight blogNews
Mar 5, 2025
Remote Monitoring and Management (RMM) Tooling Increasingly an Attacker’s First Choice | Proofpoint US

Brazilian banking malware used by TA2725 in campaigns targeting organizations mainly in Brazil, Mexico, and Spain.

Read more
mitre attack mediumNews
Apr 23, 2024
ATT&CK v15 Brings the Action: Upgraded Detections, New Analytic Format, & Cross-Domain Adversary Insights | by Amy L. Robertson | MITRE ATT&CK® | Medium

Banking trojan distributed via a malware-as-a-service model; associated with Latin American banking-trojan activity and observed impacting European entities in a recent campaign.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching26

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping29

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.