ATT&CKReferencesSCILabs Malteiro 2021

SCILabs Malteiro 2021

SCILabs. (2021, December 23). Cyber Threat Profile Malteiro. Retrieved March 13, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples27

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareMispadu

Mispadu uses a custom algorithm to obfuscate its internal strings and uses hardcoded keys.

Mispadu also uses encoded configuration files and has encoded payloads using Base64.

T1041
Exfiltration Over C2 Channel
MalwareMispadu

Mispadu can sends the collected financial data to the C2 server.

T1055
Process Injection
MalwareMispadu

Mispadu's binary is injected into memory via `WriteProcessMemory`.

T1055.001
Dynamic-link Library Injection
GroupMalteiro

Malteiro has injected Mispadu’s DLL into a process.

T1056.002
GUI Input Capture
MalwareMispadu

Mispadu can monitor browser activity for online banking actions and display full-screen overlay images to block user access to the intended site or present additional data fields.

T1059.005
Visual Basic
GroupMalteiro

Malteiro has utilized a dropper containing malicious VBS scripts.

T1059.005
Visual Basic
MalwareMispadu

Mispadu’s dropper uses VBS files to install payloads and perform execution.

T1082
System Information Discovery
GroupMalteiro

Malteiro collects the machine information, system architecture, the OS version, computer name, and Windows product name.

T1106
Native API
MalwareMispadu

Mispadu has used a variety of Windows API calls, including ShellExecute and WriteProcessMemory.

T1113
Screen Capture
MalwareMispadu

Mispadu has the ability to capture screenshots on compromised hosts.

T1140
Deobfuscate/Decode Files or Information
GroupMalteiro

Malteiro has the ability to deobfuscate downloaded files prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareMispadu

Mispadu decrypts its encrypted configuration files prior to execution.

T1204.002
Malicious File
GroupMalteiro

Malteiro has relied on users to execute .zip file attachments containing malicious URLs.

T1204.002
Malicious File
MalwareMispadu

Mispadu has relied on users to execute malicious files in order to gain execution on victim machines.

T1217
Browser Information Discovery
MalwareMispadu

Mispadu can monitor browser activity for online banking actions and display full-screen overlay images to block user access to the intended site or present additional data fields.

T1218.007
Msiexec
MalwareMispadu

Mispadu has been installed via MSI installer.

T1497.001
System Checks
MalwareMispadu

Mispadu can run checks to verify if it is running within a virtualized environments including Hyper-V, VirtualBox or VMWare and will terminate execution if the computer name is “JOHN-PC.”

T1518.001
Security Software Discovery
GroupMalteiro

Malteiro collects the installed antivirus on the victim machine.

T1555
Credentials from Password Stores
MalwareMispadu

Mispadu has obtained credentials from mail clients via NirSoft MailPassView.

T1555
Credentials from Password Stores
GroupMalteiro

Malteiro has obtained credentials from mail clients via NirSoft MailPassView.

T1555.003
Credentials from Web Browsers
MalwareMispadu

Mispadu can steal credentials from Google Chrome.

T1555.003
Credentials from Web Browsers
GroupMalteiro

Malteiro has stolen credentials stored in the victim’s browsers via software tool NirSoft WebBrowserPassView.

T1566.001
Spearphishing Attachment
GroupMalteiro

Malteiro has sent spearphishing emails containing malicious .zip files.

T1566.002
Spearphishing Link
MalwareMispadu

Mispadu has been spread via malicious links embedded in emails.

T1614.001
System Language Discovery
MalwareMispadu

Mispadu checks and will terminate execution if the compromised system’s language ID is not Spanish or Portuguese.

T1614.001
System Language Discovery
GroupMalteiro

Malteiro will terminate Mispadu's infection process if the language of the victim machine is not Spanish or Portuguese.

T1657
Financial Theft
GroupMalteiro

Malteiro targets organizations in a wide variety of sectors via the use of Mispadu banking trojan with the goal of financial theft.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.