Researchers detailed Zumanek, a Brazilian banking malware family that uses a multi-stage infection chain to steal credentials from victims of online banking and cryptocurrency services. The malware was observed almost exclusively in Brazil and begins with a socially engineered downloader that verifies the system is configured for Brazilian Portuguese, checks for installed security products, retrieves a ZIP payload from its command-and-control infrastructure, and launches the final banker and remote-access trojan stage.
The final payload abuses DLL hijacking by pairing a legitimate signed executable with a malicious DLL, then establishes persistence, injects into notepad.exe, and redirects targeted banking activity into Internet Explorer for credential theft through form grabbing. Zumanek communicates with its C2 over HTTP POST requests and multiple sockets, and supports a broad set of remote-control functions including screenshots, browser manipulation, and actions associated with keylogging, underscoring continued evolution in Brazilian financial malware.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
The analyzed Zumanek downloader sample carried a PE header compilation timestamp of 28 December 2017. ESET identified this sample as part of Zumanek version 3.0.
ESET said the Zumanek banking malware family was first detected approximately three months before the article was written, placing its initial detection around late 2017. The malware was observed almost exclusively in Brazil.
ESET publicly documented Zumanek as a new Brazilian banker malware family, detailing its multi-stage infection chain, DLL hijacking technique, persistence, browser redirection, and credential theft targeting banks and cryptocurrency services. The report also noted that Zumanek was not yet among the top 10 most detected spyware or banker families in Brazil.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.