Mispadu checks and will terminate execution if the compromised system’s language ID is not Spanish or Portuguese.
Mispadu
Mispadu is a Latin American banking trojan and stealer associated with financially motivated activity, including use by the Malteiro cluster and campaigns attributed by Proofpoint to TA2725.
Profile source: Mallory opens in a new tabMispadu
Family profile
Mispadu is a Latin American banking trojan and stealer associated with financially motivated activity, including use by the Malteiro cluster and campaigns attributed by Proofpoint to TA2725. It is one of at least 11 distinct LATAM banking trojan families identified by ESET and has been active alongside families such as Grandoreiro, Guildma, Mekotio/Casabaneiro, and others. Reporting states that TA2725 has used Brazilian banking malware including Mispadu to target organizations mainly in Brazil, Mexico, and Spain, and that a 2024 Mispadu Stealer variant targeted financial and cryptocurrency institutions in Mexico.
The malware is regionally targeted: it checks the compromised system language ID and terminates execution if the language is not Spanish or Portuguese. It has relied on user execution of malicious files to gain execution on victim machines, and related Malteiro activity used spearphishing emails with malicious ZIP attachments, VBS-based droppers, Base64-encoded scripts, and deobfuscation before execution.
Mispadu’s capabilities include monitoring browser activity for online banking actions and displaying full-screen overlay images to block access to the intended banking site or solicit additional data fields. It can steal credentials from Google Chrome, obtain credentials from mail clients via NirSoft MailPassView, list installed security products in the victim environment, capture and replace Bitcoin wallet data in the clipboard, and send collected financial data to its command-and-control server. Its binary has been reported as injected into memory via WriteProcessMemory, and it contains a copy of the OpenSSL library to encrypt C2 traffic.
High-confidence behaviors and context in the source material indicate a focus on banking fraud, credential theft, cryptocurrency theft via clipboard hijacking, and victim profiling in Spanish- and Portuguese-speaking environments, with observed targeting of financial institutions and cryptocurrency-related entities in Mexico.
Reported operators
Threat actors
2 named in public reportingTA2725 is a threat actor Proofpoint tracked since March 2022 that is known for using Brazilian banking malware (including Mispadu, Astaroth, and historically Grandoreiro) and credential phishing to target organizations mainly in Brazil, Mexico, and Spain.
MITRE ATT&CK
Mispadu in ATT&CK
42 distinct techniquesTechniques
42 techniquesReporting