Garcia, F., Regalado, D. (2023, March 7). Inside Mispadu massive infection campaign in LATAM. Retrieved March 15, 2024.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1056.001 Keylogging |
MalwareMispadu | Mispadu can log keystrokes on the victim's machine. |
| T1113 Screen Capture |
MalwareMispadu | Mispadu has the ability to capture screenshots on compromised hosts. |
| T1204.002 Malicious File |
MalwareMispadu | Mispadu has relied on users to execute malicious files in order to gain execution on victim machines. |
| T1518.001 Security Software Discovery |
MalwareMispadu | Mispadu can list installed security products in the victim’s environment. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMispadu | Mispadu creates a link in the startup folder for persistence. Mispadu adds persistence via the registry key `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`. |
| T1555.003 Credentials from Web Browsers |
MalwareMispadu | Mispadu can steal credentials from Google Chrome. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.