Zumanek is a Latin American banking malware family focused on Brazil and historically observed almost exclusively there until the middle of 2020. It is a Windows banker with remote-access functionality, designed to give operators interactive control over infected systems while stealing credentials for Brazilian online banking services and selected cryptocurrency exchanges. It has been identified as one of the distinct but closely related Latin American banking trojan families that share tooling, execution patterns, and obfuscation approaches.
Zumanek commonly uses a multi-stage infection chain. Initial compromise relies on social engineering, and broader reporting on this malware cluster indicates spam-based delivery is the dominant distribution method. In analyzed Zumanek infections, a first-stage downloader profiles the victim machine, verifies that the system is configured for Brazilian Portuguese, checks for the presence of several security products, and aborts if those protections are detected. It then retrieves a ZIP archive containing the final payload, extracts it, and launches the banker stage.
The final payload uses DLL side-loading or DLL hijacking by pairing a legitimate signed executable with a malicious DLL. After execution, Zumanek establishes persistence through a Run-key mechanism, creates a new process, and injects itself so that its malicious logic runs from the injected process. It communicates with operators through an initial HTTP-based registration channel and additional socket-based channels used for command handling, text interaction, and screenshot transfer. Reported operator capabilities include remote desktop-style control, browser manipulation, screenshot capture, keyboard-related monitoring functions, and institution-specific fraud workflows.
Zumanek monitors for targeted financial activity and redirects access from common browsers to Internet Explorer in order to present fraudulent forms and capture credentials. Its targeting has included numerous Brazilian financial institutions as well as cryptocurrency trading services. The malware also performs host reconnaissance, gathers system and security-product information, and uses custom string obfuscation and packing to hinder analysis. Zumanek is associated with the broader ecosystem of Brazilian banking trojans that rely on manual operator involvement during the fraud stage rather than fully automated theft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
38 distinct techniques documented for this family, organized by ATT&CK tactic.
T1059.007 Command and Scripting Interpreter: JavaScript/JScript ✅ ✅ ❌ ✅ ❌ ❌ ✅ ✅ ❌ ✅ ✅ ✅
Para chegar às vítimas, os cibercriminosos se valem da Engenharia Social a fim de convencer a vítima a baixar e executar esse primeiro estágio de infecção.
os desenvolvedores do Zumanek... utilizam o packer PECompact... essas strings estão encriptadas... implementado exclusivamente para dificultar a análise estática do código.
The executable was very often protected by either the VMProtect or Armadillo packer.
T1036.005 Masquerading: Match Legitimate Name or Location ❌ ✅ ✅ ✅ ❌ ❌ ❌ ✅ ❌ ❌ ❌ ✅
o módulo cria um novo processo de notepad.EXE e injeta-se na memória do mesmo.
they all obfuscate either payloads or configuration data in some way
since 2019, the vast majority of these malware families started to utilize Windows Installer (MSI files) as the first stage of the distribution chain
Listagem completa de AVs/proteções verificados: ... SbieDll.dll (Sandboxie)
Operators need to react to this situation and manually command the malware to display the fake pop-up window and take control of the victim’s machine
Através do socket Comando, o operador do Zumanek pode enviar diversos comandos... ATIVAKEYLOG DESATIVAKEYLOG RECEBERDADOSKEY
periodically scanning active windows based on name or title
T1082 System Information Discovery ✅ ✅ ✅ ✅ ✅ ✅ ✅ ✅ ✅ ✅ ✅ ✅
Listagem completa de AVs/proteções verificados: ... SbieDll.dll (Sandboxie)
Além disso, antes de tentar fazer o download de qualquer arquivo, o Downloader verifica a presença de diferentes antivírus. Caso algum deles seja detectado, o processo é imediatamente encerrado.
Operators need to react to this situation and manually command the malware to display the fake pop-up window and take control of the victim’s machine
Através do socket Comando, o operador do Zumanek pode enviar diversos comandos... ATIVAKEYLOG DESATIVAKEYLOG RECEBERDADOSKEY
to steal credentials, they tend to use either fake pop-up windows or keyloggers
injetando formulários (form grabbing) para roubar as senhas de acesso das vítimas e enviá-las ao C&C.
A comunicação inicial com o C&C dá-se através de requisições HTTP POST...
Além da comunicação via HTTP POST, três sockets são criados: Comando, Foto e Texto.
No primeiro estágio do Zumanek... realizar o download do payload final... Execução de urlmon.URLDownloadToFileW para download do payload final.
T1132.001 Data Encoding: Standard Encoding ❌ ✅ ✅ ✅ ✅ ❌ ❌ ❌ ❌ ❌ ✅ ✅
custom encryption algorithms are favored over established ones
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Dormant Latin American banking trojan family active in Brazil, notable for string obfuscation via per-character functions and simple ZIP-based delivery; possibly a predecessor to Ousaban.
Latin American banking trojan family identified as part of a cluster of related banking trojans with common delivery, execution, and credential theft behaviors.
Malware family focused almost exclusively on Brazil. It uses a multi-stage infection chain with a downloader that checks for pt-BR language settings, detects security products, downloads a ZIP payload, and executes the final stage. The final stage is a banker/RAT that uses DLL hijacking, persistence via Run registry key, process injection into notepad.exe, browser redirection, form grabbing, screenshot streaming, keylogging-related commands, and remote control to steal online banking and cryptocurrency exchange credentials.
Latin American banking trojan that follows the common Delphi-based banking-trojan design of victim registration, banking-window monitoring, and fake pop-up credential theft. It shares a custom encryption scheme with multiple families and has used direct execution in the past.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.