Mispadu

S1122

Malware.View on attack.mitre.org

About this malware

Mispadu is a banking trojan written in Delphi that was first observed in 2019 and uses a Malware-as-a-Service (MaaS) business model. This malware is operated, managed, and sold by the Malteiro cybercriminal group. Mispadu has mainly been used to target victims in Brazil and Mexico, and has also had confirmed operations throughout Latin America and Europe.

Techniques used26

Procedure examples26

TechniqueProcedure example
T1027.013
Encrypted/Encoded File

Mispadu uses a custom algorithm to obfuscate its internal strings and uses hardcoded keys.

Mispadu also uses encoded configuration files and has encoded payloads using Base64.

T1041
Exfiltration Over C2 Channel

Mispadu can sends the collected financial data to the C2 server.

T1055
Process Injection

Mispadu's binary is injected into memory via `WriteProcessMemory`.

T1056.001
Keylogging

Mispadu can log keystrokes on the victim's machine.

T1056.002
GUI Input Capture

Mispadu can monitor browser activity for online banking actions and display full-screen overlay images to block user access to the intended site or present additional data fields.

T1057
Process Discovery

Mispadu can enumerate the running processes on a compromised host.

T1059.005
Visual Basic

Mispadu’s dropper uses VBS files to install payloads and perform execution.

T1082
System Information Discovery

Mispadu collects the OS version, computer name, and language ID.

T1083
File and Directory Discovery

Mispadu searches for various filesystem paths to determine what banking applications are installed on the victim’s machine.

T1106
Native API

Mispadu has used a variety of Windows API calls, including ShellExecute and WriteProcessMemory.

T1113
Screen Capture

Mispadu has the ability to capture screenshots on compromised hosts.

T1115
Clipboard Data

Mispadu has the ability to capture and replace Bitcoin wallet data in the clipboard on a compromised host.

T1140
Deobfuscate/Decode Files or Information

Mispadu decrypts its encrypted configuration files prior to execution.

T1176.001
Browser Extensions

Mispadu utilizes malicious Google Chrome browser extensions to steal financial data.

T1204.002
Malicious File

Mispadu has relied on users to execute malicious files in order to gain execution on victim machines.

View all 26 procedure examples

Groups that use it1

Campaigns0

None recorded.

References4

  1. ESET Security Mispadu Facebook Ads 2019 Open source
    ESET Security. (2019, November 19). Mispadu: Advertisement for a discounted Unhappy Meal. Retrieved March 13, 2024.
  2. SCILabs Malteiro 2021 Open source
    SCILabs. (2021, December 23). Cyber Threat Profile Malteiro. Retrieved March 13, 2024.
  3. SCILabs URSA/Mispadu Evolution 2023 Open source
    SCILabs. (2023, May 23). Evolution of banking trojan URSA/Mispadu. Retrieved March 13, 2024.
  4. Segurança Informática URSA Sophisticated Loader 2020 Open source
    Pedro Tavares (Segurança Informática). (2020, September 15). Threat analysis: The emergent URSA trojan impacts many countries using a sophisticated loader. Retrieved March 13, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.