Malteiro is malware associated in the provided content with Mispadu infection activity. It performs victim profiling and targeting checks, including collecting installed antivirus products and system information such as machine information, system architecture, OS version, computer name, and Windows product name. It also checks the victim machine language and terminates the Mispadu infection process if the language is not Spanish or Portuguese. The malware has been distributed via spearphishing emails containing malicious .zip attachments and has relied on users to execute .zip file attachments containing malicious URLs. The content states that Malteiro can deobfuscate downloaded files prior to execution and has used scripts encoded in Base64 certificates to distribute malware. For credential theft, it has stolen credentials stored in browsers using NirSoft WebBrowserPassView and obtained credentials from mail clients via NirSoft MailPassView. The only alias directly provided in the content is "malteiro."
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
27 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a threat actor associated with the PowerShell P/Invoke process injection API chain detection and related ATT&CK techniques.
Listed as a threat actor associated with the malicious file execution technique detected by this analytic.
Listed in the detection annotations as a threat actor associated with EFI volume mounting / installation-related behavior.
Listed as a threat actor associated with WinPEAS-related post-exploitation/reconnaissance activity in the detection metadata.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.