Skip to content

Mispadu

Mispadu is a Latin American banking trojan and stealer associated with financially motivated activity, including use by the Malteiro cluster and campaigns attributed by Proofpoint to TA2725.

Profile source: Mallory opens in a new tab

Mispadu

Family profile

Mispadu is a Latin American banking trojan and stealer associated with financially motivated activity, including use by the Malteiro cluster and campaigns attributed by Proofpoint to TA2725. It is one of at least 11 distinct LATAM banking trojan families identified by ESET and has been active alongside families such as Grandoreiro, Guildma, Mekotio/Casabaneiro, and others. Reporting states that TA2725 has used Brazilian banking malware including Mispadu to target organizations mainly in Brazil, Mexico, and Spain, and that a 2024 Mispadu Stealer variant targeted financial and cryptocurrency institutions in Mexico.

The malware is regionally targeted: it checks the compromised system language ID and terminates execution if the language is not Spanish or Portuguese. It has relied on user execution of malicious files to gain execution on victim machines, and related Malteiro activity used spearphishing emails with malicious ZIP attachments, VBS-based droppers, Base64-encoded scripts, and deobfuscation before execution.

Mispadu’s capabilities include monitoring browser activity for online banking actions and displaying full-screen overlay images to block access to the intended banking site or solicit additional data fields. It can steal credentials from Google Chrome, obtain credentials from mail clients via NirSoft MailPassView, list installed security products in the victim environment, capture and replace Bitcoin wallet data in the clipboard, and send collected financial data to its command-and-control server. Its binary has been reported as injected into memory via WriteProcessMemory, and it contains a copy of the OpenSSL library to encrypt C2 traffic.

High-confidence behaviors and context in the source material indicate a focus on banking fraud, credential theft, cryptocurrency theft via clipboard hijacking, and victim profiling in Spanish- and Portuguese-speaking environments, with observed targeting of financial institutions and cryptocurrency-related entities in Mexico.

Reported operators

Threat actors

2 named in public reporting
Malteiro

Mispadu checks and will terminate execution if the compromised system’s language ID is not Spanish or Portuguese.

TA2725

TA2725 is a threat actor Proofpoint tracked since March 2022 that is known for using Brazilian banking malware (including Mispadu, Astaroth, and historically Grandoreiro) and credential phishing to target organizations mainly in Brazil, Mexico, and Spain.

MITRE ATT&CK

Mispadu in ATT&CK

42 distinct techniques

Reporting

Research mentioning Mispadu

Jul 15
Esentire

DinDoor, DenoRAT, and NightshadeC2: Analyzing TAG-150's Evolving Tradecraft | eSentire

eSentire reported that a June 2026 intrusion against a finance-sector customer began with a ClickFix-style social engineering lure that triggered a malicious command, an MSI installer, and a multi-stage malware chain attributed to TAG-150. The infection sequence used an apparently AI-generated PowerShell script, Griffin20.ps1, to install the Deno runtime and launch the Deno-based loader DinDoor, which then deployed DenoRAT and ultimately NightshadeC2. Investigators said the malware communicated with command-and-control infrastructure including webstizkgao[.]com and used hard-coded JWTs carrying campaign identifiers such as buildId 0def066f14754be9 and buildNote LearnV7msi. The tooling provided broad post-compromise capability, with DenoRAT functioning as a RAT, loader, and stealer that supported command execution, persistence, host fingerprinting, file operations, screenshots, PTY and VNC-style remote control, and theft from browsers and cryptocurrency wallets. eSentire said the malware could also bypass Chromium App-Bound Encryption through DLL injection, a technique widely associated with in-memory execution, evasion, and abuse of legitimate Windows processes in ATT&CK T1055.001. The final NightshadeC2 payload was delivered through a PowerShell-driven Python in-memory loader, decrypted from an encrypted container using AES-256-CBC with a key derived from MoscauHighSmoke, and reflectively mapped into a Python process before the affected host was isolated and remediated.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.