Malware.View on attack.mitre.org
Metamorfo is a Latin-American banking trojan operated by a Brazilian cybercrime group that has been active since at least April 2018. The group focuses on targeting banks and cryptocurrency services in Brazil and Mexico.
| Technique | Procedure example |
|---|---|
| T1010 Application Window Discovery |
Metamorfo can enumerate all windows on the victim’s machine. |
| T1027.002 Software Packing |
Metamorfo has used VMProtect to pack and protect files. |
| T1027.013 Encrypted/Encoded File |
Metamorfo has encrypted payloads and strings. |
| T1033 System Owner/User Discovery |
Metamorfo has collected the username from the victim's machine. |
| T1036.005 Match Legitimate Resource Name or Location |
Metamorfo has disguised an MSI file as the Adobe Acrobat Reader Installer and has masqueraded payloads as OneDrive, WhatsApp, or Spotify, for example. |
| T1041 Exfiltration Over C2 Channel |
Metamorfo can send the data it collects to the C2 server. |
| T1055.001 Dynamic-link Library Injection |
Metamorfo has injected a malicious DLL into the Windows Media Player process (wmplayer.exe). |
| T1056.001 Keylogging |
Metamorfo has a command to launch a keylogger and capture keystrokes on the victim’s machine. |
| T1056.002 GUI Input Capture |
Metamorfo has displayed fake forms on top of banking sites to intercept credentials from victims. |
| T1057 Process Discovery |
Metamorfo has performed process name checks and has monitored applications. |
| T1059.003 Windows Command Shell |
Metamorfo has used |
| T1059.005 Visual Basic |
Metamorfo has used VBS code on victims’ systems. |
| T1059.007 JavaScript |
Metamorfo includes payloads written in JavaScript. |
| T1070 Indicator Removal |
Metamorfo has a command to delete a Registry key it uses, |
| T1070.004 File Deletion |
Metamorfo has deleted itself from the system after execution. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.