ATT&CKGroupsMalteiro

Malteiro

G1026

Threat group.View on attack.mitre.org

About this group

Malteiro is a financially motivated criminal group that is likely based in Brazil and has been active since at least November 2019. The group operates and distributes the Mispadu banking trojan via a Malware-as-a-Service (MaaS) business model. Malteiro mainly targets victims throughout Latin America (particularly Mexico) and Europe (particularly Spain and Portugal).

Techniques used12

Procedure examples12

TechniqueProcedure example
T1027.013
Encrypted/Encoded File

Malteiro has used scripts encoded in Base64 certificates to distribute malware to victims.

T1055.001
Dynamic-link Library Injection

Malteiro has injected Mispadu’s DLL into a process.

T1059.005
Visual Basic

Malteiro has utilized a dropper containing malicious VBS scripts.

T1082
System Information Discovery

Malteiro collects the machine information, system architecture, the OS version, computer name, and Windows product name.

T1140
Deobfuscate/Decode Files or Information

Malteiro has the ability to deobfuscate downloaded files prior to execution.

T1204.002
Malicious File

Malteiro has relied on users to execute .zip file attachments containing malicious URLs.

T1518.001
Security Software Discovery

Malteiro collects the installed antivirus on the victim machine.

T1555
Credentials from Password Stores

Malteiro has obtained credentials from mail clients via NirSoft MailPassView.

T1555.003
Credentials from Web Browsers

Malteiro has stolen credentials stored in the victim’s browsers via software tool NirSoft WebBrowserPassView.

T1566.001
Spearphishing Attachment

Malteiro has sent spearphishing emails containing malicious .zip files.

T1614.001
System Language Discovery

Malteiro will terminate Mispadu's infection process if the language of the victim machine is not Spanish or Portuguese.

T1657
Financial Theft

Malteiro targets organizations in a wide variety of sectors via the use of Mispadu banking trojan with the goal of financial theft.

Software1

Campaigns0

None recorded.

References1

  1. SCILabs Malteiro 2021 Open source
    SCILabs. (2021, December 23). Cyber Threat Profile Malteiro. Retrieved March 13, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.