Mispadu is a Latin American banking trojan and stealer associated with financially motivated activity, including use by the Malteiro cluster and campaigns attributed by Proofpoint to TA2725. It is one of at least 11 distinct LATAM banking trojan families identified by ESET and has been active alongside families such as Grandoreiro, Guildma, Mekotio/Casabaneiro, and others. Reporting states that TA2725 has used Brazilian banking malware including Mispadu to target organizations mainly in Brazil, Mexico, and Spain, and that a 2024 Mispadu Stealer variant targeted financial and cryptocurrency institutions in Mexico.
The malware is regionally targeted: it checks the compromised system language ID and terminates execution if the language is not Spanish or Portuguese. It has relied on user execution of malicious files to gain execution on victim machines, and related Malteiro activity used spearphishing emails with malicious ZIP attachments, VBS-based droppers, Base64-encoded scripts, and deobfuscation before execution.
Mispadu’s capabilities include monitoring browser activity for online banking actions and displaying full-screen overlay images to block access to the intended banking site or solicit additional data fields. It can steal credentials from Google Chrome, obtain credentials from mail clients via NirSoft MailPassView, list installed security products in the victim environment, capture and replace Bitcoin wallet data in the clipboard, and send collected financial data to its command-and-control server. Its binary has been reported as injected into memory via WriteProcessMemory, and it contains a copy of the OpenSSL library to encrypt C2 traffic.
High-confidence behaviors and context in the source material indicate a focus on banking fraud, credential theft, cryptocurrency theft via clipboard hijacking, and victim profiling in Spanish- and Portuguese-speaking environments, with observed targeting of financial institutions and cryptocurrency-related entities in Mexico.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Mispadu checks and will terminate execution if the compromised system’s language ID is not Spanish or Portuguese.
TA2725 is a threat actor Proofpoint tracked since March 2022 that is known for using Brazilian banking malware (including Mispadu, Astaroth, and historically Grandoreiro) and credential phishing to target organizations mainly in Brazil, Mexico, and Spain.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware using VBScript, VBS, VBA macros, and Visual Basic code for execution, payload delivery, persistence, reconnaissance, and command execution.
The content repeatedly describes victims being lured into opening malicious attachments, enabling macros, launching installers, clicking embedded files/links, or otherwise directly executing malicious content.
Sandworm Team leveraged Microsoft Office attachments which contained malicious macros that were automatically executed once the user permitted them... APT29 has used various forms of spearphishing attempting to get a user to open attachments... DarkGate is distributed through phishing links to VBS or MSI objects requiring user interaction for execution.
Across the content, malware repeatedly 'adds Registry Run keys', 'creates Registry entries', 'modifies the Windows Registry', or 'overwrites registry keys' to maintain persistence.
The content repeatedly describes adversaries and malware injecting code, shellcode, DLLs, or payloads into legitimate processes such as svchost.exe, explorer.exe, iexplore.exe, wuauclt.exe, lsass.exe, and browser processes.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
The content repeatedly describes adversaries and malware injecting code, shellcode, DLLs, or payloads into legitimate processes such as svchost.exe, explorer.exe, iexplore.exe, wuauclt.exe, lsass.exe, and browser processes.
The content repeatedly describes malware and threat actors decoding, decrypting, deobfuscating, or unpacking payloads, strings, configuration data, commands, and C2 responses prior to execution or use.
“AppleJeus delivered components using a Windows Installer package (.msi)… executed the 3CXDesktopApp.exe…”, “APT38 has used msiexec.exe to execute malicious files.”, “Rancor has used msiexec to download and execute malicious installer files over HTTP.”, “TA505 has used msiexec to download and execute malicious Windows Installer files.”
“Mispadu can monitor browser activity for online banking actions and display full-screen overlay images...”
Metamorfo has displayed fake forms on top of banking sites to intercept credentials from victims. Mispadu can monitor browser activity for online banking actions and display full-screen overlay images to block user access to the intended site or present additional data fields.
Agent Tesla has the ability to steal credentials from FTP clients and wireless profiles... APT33 has used a variety of publicly available tools like LaZagne to gather credentials... Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the credential vault and DPAPI.
The content repeatedly describes threat actors and malware stealing usernames, passwords, cookies, session tokens, and other saved credentials from web browsers such as Chrome, Firefox, Internet Explorer, Edge, Opera, Safari, and Yandex.
Evilnum can collect email credentials from victims... Malteiro has obtained credentials from mail clients via NirSoft MailPassView... MgBot includes modules for stealing stored credentials from Outlook and Foxmail email client software... PLEAD has the ability to steal saved passwords from Microsoft Outlook.
The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
“...leveraged ICONICSTEALER to steal browser information to include browser history...” / “...collected browser bookmark information...” / “...retrieve browser history...” / “...gather browser data such as bookmarks and visited sites...”
Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment.
Avaddon checks for specific keyboard layouts and OS languages to avoid targeting Commonwealth of Independent States (CIS) entities... Bazar can perform a check to ensure that the operating system's keyboard and language settings are not set to Russian... Clop has checked the keyboard language using the GetKeyboardLayout() function... Ryuk has been observed to query the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\Language and the value InstallLanguage.
“Mispadu can monitor browser activity for online banking actions and display full-screen overlay images...”
Metamorfo has displayed fake forms on top of banking sites to intercept credentials from victims. Mispadu can monitor browser activity for online banking actions and display full-screen overlay images to block user access to the intended site or present additional data fields.
The content repeatedly describes malware and threat actors using SSL, TLS, HTTPS, RSA, AES, Blowfish, RC4, ECIES, Diffie-Hellman, OpenSSL, WolfSSL, and mutual TLS to protect command and control traffic.
Multiple malware families and intrusion sets are described as encrypting C2 traffic using SSL/TLS/HTTPS (e.g., "used HTTPS for command and control", "encrypts C2 communications with TLS", "uses SSL for encrypting C2 communications", "TLS-encrypted WebSocket Protocol (WSS) for C2").
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
26 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
46 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Banking trojan/stealer targeting financial and cryptocurrency institutions in Mexico.
Banking trojan targeting Latin America (notably Mexico and Brazil) delivered via phishing with HTA attachments (sometimes via password-protected PDFs); uses an AutoIT loader and dynamically generated delivery artifacts to frustrate EDR; includes self-propagation via email and expanded targeting to banks outside LATAM and crypto exchanges.
Banking trojan targeting Latin America (and expanding beyond) delivered via phishing with HTA attachments; uses an AutoIT loader and legitimate files; can self-propagate via email and targets online banking sites and cryptocurrency exchanges.
Brazilian banking malware used by TA2725 in campaigns targeting organizations mainly in Brazil, Mexico, and Spain.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.