ATT&CKReferencesMetabase Q Mispadu Trojan 2023

Metabase Q Mispadu Trojan 2023

Garcia, F., Regalado, D. (2023, March 7). Inside Mispadu massive infection campaign in LATAM. Retrieved March 15, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1056.001
Keylogging
MalwareMispadu

Mispadu can log keystrokes on the victim's machine.

T1113
Screen Capture
MalwareMispadu

Mispadu has the ability to capture screenshots on compromised hosts.

T1204.002
Malicious File
MalwareMispadu

Mispadu has relied on users to execute malicious files in order to gain execution on victim machines.

T1518.001
Security Software Discovery
MalwareMispadu

Mispadu can list installed security products in the victim’s environment.

T1547.001
Registry Run Keys / Startup Folder
MalwareMispadu

Mispadu creates a link in the startup folder for persistence. Mispadu adds persistence via the registry key `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`.

T1555.003
Credentials from Web Browsers
MalwareMispadu

Mispadu can steal credentials from Google Chrome.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.