Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
Its most noticeable characteristic was its usage of well-known cryptographic methods to encrypt strings... Zumanek is identified by its method for obfuscating strings.
periodically scanning active windows based on name or title
T1082 System Information Discovery ✅ ✅ ✅ ✅ ✅ ✅ ✅ ✅ ✅ ✅ ✅ ✅
T1083 File and Directory Discovery ✅ ✅ ✅ ✅ ✅ ✅ ✅ ✅ ✅ ❌ ❌ ❌
Operators need to react to this situation and manually command the malware to display the fake pop-up window and take control of the victim’s machine
to steal credentials, they tend to use either fake pop-up windows or keyloggers
Its downloaders simply downloaded a ZIP archive containing only the banking trojan executable
T1132.001 Data Encoding: Standard Encoding ❌ ✅ ✅ ✅ ✅ ❌ ❌ ❌ ❌ ❌ ✅ ✅
custom encryption algorithms are favored over established ones
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Dormant Latin American banking trojan family active in Brazil until mid-2019, notable for using standard cryptographic algorithms for string encryption and a Go-based downloader.
Latin American banking trojan family included in ESET's comparative analysis of closely related banking trojans sharing common TTPs.
Latin American banking trojan that adheres to the common regional banking-trojan blueprint and has used DLL side-loading for execution. The report notes it appears to share the least with the other families compared with more interlinked families like Casbaneiro, Mekotio, and Vadokrist.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.