SCILabs. (2021, December 23). Cyber Threat Profile Malteiro. Retrieved March 13, 2024.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
MalwareMispadu | Mispadu uses a custom algorithm to obfuscate its internal strings and uses hardcoded keys. Mispadu also uses encoded configuration files and has encoded payloads using Base64. |
| T1041 Exfiltration Over C2 Channel |
MalwareMispadu | Mispadu can sends the collected financial data to the C2 server. |
| T1055 Process Injection |
MalwareMispadu | Mispadu's binary is injected into memory via `WriteProcessMemory`. |
| T1055.001 Dynamic-link Library Injection |
GroupMalteiro | |
| T1056.002 GUI Input Capture |
MalwareMispadu | Mispadu can monitor browser activity for online banking actions and display full-screen overlay images to block user access to the intended site or present additional data fields. |
| T1059.005 Visual Basic |
GroupMalteiro | Malteiro has utilized a dropper containing malicious VBS scripts. |
| T1059.005 Visual Basic |
MalwareMispadu | Mispadu’s dropper uses VBS files to install payloads and perform execution. |
| T1082 System Information Discovery |
GroupMalteiro | Malteiro collects the machine information, system architecture, the OS version, computer name, and Windows product name. |
| T1106 Native API |
MalwareMispadu | Mispadu has used a variety of Windows API calls, including ShellExecute and WriteProcessMemory. |
| T1113 Screen Capture |
MalwareMispadu | Mispadu has the ability to capture screenshots on compromised hosts. |
| T1140 Deobfuscate/Decode Files or Information |
GroupMalteiro | Malteiro has the ability to deobfuscate downloaded files prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareMispadu | Mispadu decrypts its encrypted configuration files prior to execution. |
| T1204.002 Malicious File |
GroupMalteiro | Malteiro has relied on users to execute .zip file attachments containing malicious URLs. |
| T1204.002 Malicious File |
MalwareMispadu | Mispadu has relied on users to execute malicious files in order to gain execution on victim machines. |
| T1217 Browser Information Discovery |
MalwareMispadu | Mispadu can monitor browser activity for online banking actions and display full-screen overlay images to block user access to the intended site or present additional data fields. |
| T1218.007 Msiexec |
MalwareMispadu | Mispadu has been installed via MSI installer. |
| T1497.001 System Checks |
MalwareMispadu | Mispadu can run checks to verify if it is running within a virtualized environments including Hyper-V, VirtualBox or VMWare and will terminate execution if the computer name is “JOHN-PC.” |
| T1518.001 Security Software Discovery |
GroupMalteiro | Malteiro collects the installed antivirus on the victim machine. |
| T1555 Credentials from Password Stores |
MalwareMispadu | Mispadu has obtained credentials from mail clients via NirSoft MailPassView. |
| T1555 Credentials from Password Stores |
GroupMalteiro | Malteiro has obtained credentials from mail clients via NirSoft MailPassView. |
| T1555.003 Credentials from Web Browsers |
MalwareMispadu | Mispadu can steal credentials from Google Chrome. |
| T1555.003 Credentials from Web Browsers |
GroupMalteiro | Malteiro has stolen credentials stored in the victim’s browsers via software tool NirSoft WebBrowserPassView. |
| T1566.001 Spearphishing Attachment |
GroupMalteiro | Malteiro has sent spearphishing emails containing malicious .zip files. |
| T1566.002 Spearphishing Link |
MalwareMispadu | Mispadu has been spread via malicious links embedded in emails. |
| T1614.001 System Language Discovery |
MalwareMispadu | Mispadu checks and will terminate execution if the compromised system’s language ID is not Spanish or Portuguese. |
| T1614.001 System Language Discovery |
GroupMalteiro | Malteiro will terminate Mispadu's infection process if the language of the victim machine is not Spanish or Portuguese. |
| T1657 Financial Theft |
GroupMalteiro | Malteiro targets organizations in a wide variety of sectors via the use of Mispadu banking trojan with the goal of financial theft. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.