Malware.View on attack.mitre.org
Mispadu is a banking trojan written in Delphi that was first observed in 2019 and uses a Malware-as-a-Service (MaaS) business model. This malware is operated, managed, and sold by the Malteiro cybercriminal group. Mispadu has mainly been used to target victims in Brazil and Mexico, and has also had confirmed operations throughout Latin America and Europe.
| Technique | Procedure example |
|---|---|
| T1027.013 Encrypted/Encoded File |
Mispadu uses a custom algorithm to obfuscate its internal strings and uses hardcoded keys. Mispadu also uses encoded configuration files and has encoded payloads using Base64. |
| T1041 Exfiltration Over C2 Channel |
Mispadu can sends the collected financial data to the C2 server. |
| T1055 Process Injection |
Mispadu's binary is injected into memory via `WriteProcessMemory`. |
| T1056.001 Keylogging |
Mispadu can log keystrokes on the victim's machine. |
| T1056.002 GUI Input Capture |
Mispadu can monitor browser activity for online banking actions and display full-screen overlay images to block user access to the intended site or present additional data fields. |
| T1057 Process Discovery |
Mispadu can enumerate the running processes on a compromised host. |
| T1059.005 Visual Basic |
Mispadu’s dropper uses VBS files to install payloads and perform execution. |
| T1082 System Information Discovery |
Mispadu collects the OS version, computer name, and language ID. |
| T1083 File and Directory Discovery |
Mispadu searches for various filesystem paths to determine what banking applications are installed on the victim’s machine. |
| T1106 Native API |
Mispadu has used a variety of Windows API calls, including ShellExecute and WriteProcessMemory. |
| T1113 Screen Capture |
Mispadu has the ability to capture screenshots on compromised hosts. |
| T1115 Clipboard Data |
Mispadu has the ability to capture and replace Bitcoin wallet data in the clipboard on a compromised host. |
| T1140 Deobfuscate/Decode Files or Information |
Mispadu decrypts its encrypted configuration files prior to execution. |
| T1176.001 Browser Extensions |
Mispadu utilizes malicious Google Chrome browser extensions to steal financial data. |
| T1204.002 Malicious File |
Mispadu has relied on users to execute malicious files in order to gain execution on victim machines. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.