Numando is a Latin American banking trojan written in Delphi and active since at least 2018. It primarily targets victims in Brazil, with less frequent campaigns against Mexico and Spain. It belongs to the broader cluster of LATAM banking trojans that share overlapping tradecraft, including MSI-based delivery, ZIP-packaged components, DLL side-loading, custom string encryption, and operator-driven fraud using institution-themed overlay windows.
Numando is distributed almost exclusively through spam campaigns. Observed delivery chains commonly use ZIP attachments containing MSI installers. A typical infection deploys a legitimate application, an injector, and an encrypted Numando payload; execution occurs when the legitimate application side-loads the injector, which decrypts and launches the banking trojan. Some campaigns have also used a Delphi downloader that retrieves a decoy archive and extracts an encrypted URL from ZIP metadata to obtain the real payload. In another observed variant, the final payload was concealed inside image overlay data and extracted by the injector at runtime.
The malware is designed for interactive banking fraud rather than fully automated theft. It monitors for targeted activity and displays fake overlay windows intended to trick victims into entering sensitive information. Supported backdoor-style functions include simulating mouse and keyboard input, taking screenshots, terminating browser processes, displaying overlays, and restarting or shutting down the infected system. Numando also collects basic host information, including Windows version and system architecture.
Numando uses numeric command identifiers instead of string-based commands and stores remote configuration data on public services, with configuration entries encrypted using keys embedded in the malware. Variants have stored overlay resources either in encrypted archives embedded in resources or in separate Delphi DLLs. Compared with some higher-volume LATAM banking trojans, Numando appears less prevalent and shows relatively limited evolution over time, but it remains a persistent threat within the regional banking-trojan ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
The injector locates the payload and then decrypts it using a simple XOR algorithm with a multi-byte key... Numando encrypts its payload or hides it inside a BMP image file, and some variants encrypt and hex encode their main payload URLs in a comment in decoy ZIP files.
Operators need to react to this situation and manually command the malware to display the fake pop-up window and take control of the victim’s machine
to steal credentials, they tend to use either fake pop-up windows or keyloggers
Operators need to react to this situation and manually command the malware to display the fake pop-up window and take control of the victim’s machine
to steal credentials, they tend to use either fake pop-up windows or keyloggers
Strings are encrypted... The format is simple – three entries delimited by “:” between the DATA:{ and } markers. Each entry is encrypted separately... T1132.002 Data Encoding: Non-Standard Encoding Numando uses custom encryption.
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Latin American banking trojan family included among the active families tracked by ESET in this series.
A Latin American banking trojan written in Delphi that primarily targets Brazilian victims using spam-delivered MSI installers, DLL side-loading, fake overlay windows, and backdoor capabilities including simulated mouse/keyboard actions, screenshots, browser process termination, and system restart/shutdown. It also abuses YouTube and Pastebin for remote configuration storage and has used decoy ZIP archives and BMP overlays to conceal payload delivery.
Latin American banking trojan family discussed as part of a broader ecosystem of cooperating banking malware operators.
Latin American banking trojan that follows the shared regional banking-trojan architecture and uses fake pop-up windows for credential theft. It shares a custom string-encryption scheme with several other families and has used DLL side-loading.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.