DIRECTORY

  • Alerts
  • APTs
  • Blog
  • Books
  • Certifications
  • Cheat Sheets
  • Courses
  • Cyber Briefing
  • CyberDecoded
  • CyberReview
  • CyberStory
  • CyberTips
  • Definitions
  • Domains
  • Entertainment
  • FAQ
  • Frameworks
  • Hardware Tools
  • Incidents
  • Malware
  • News
  • Papers
  • Podcasts
  • Quotes
  • Reports
  • Tools
  • Threats
  • Tutorials
No Result
View All Result
  • Login
  • Register
  • Cyber Citizens
  • Cyber Professionals
  • Institutions
CyberMaterial
Get Help
  • Cyber Citizens
  • Cyber Professionals
  • Institutions
CyberMaterial
No Result
View All Result
Get Help
CyberMaterial
Home Incidents

Mispadu trojan targets LATAM countries

March 21, 2023
Reading Time: 2 mins read
in Incidents

 

Latin American cybersecurity firm Metabase Q has reported that a banking trojan called Mispadu has been linked to multiple spam campaigns in countries such as Bolivia, Chile, Mexico, Peru, and Portugal.

Mispadu, also known as URSA, was first documented by ESET in November 2019 and can perpetrate monetary and credential theft and act as a backdoor by taking screenshots and capturing keystrokes.

The trojan has also been found to share similarities with other banking trojans targeting the region, like Grandoreiro, Javali, and Lampion.

The hackers use various techniques to infect devices and steal data, one of which involves compromising legitimate websites to turn them into their command-and-control server to spread malware.

They filter out countries they do not wish to infect and drop different types of malware based on the country being infected. The attack chains involving the Delphi malware leverage email messages urging recipients to open fake overdue invoices, thereby triggering a multi-stage infection process.

Mispadu can gather the list of antivirus solutions installed on the compromised host, siphon credentials from Google Chrome and Microsoft Outlook, and facilitate the retrieval of additional malware.

This includes an obfuscated Visual Basic Script dropper that serves to download another payload from a hard-coded domain, a .NET-based remote access tool that can run commands issued by an actor-controlled server, and a loader written in Rust that executes a PowerShell loader to run files directly from memory. Additionally, the malware uses malicious overlay screens to obtain credentials associated with online banking portals and other sensitive information.

According to Metabase Q, the certutil approach has allowed Mispadu to bypass detection by a wide range of security software and harvest over 90,000 bank account credentials from over 17,500 unique websites.

The researchers recommend that users keep their antivirus software updated, avoid clicking on suspicious links or attachments, and enable two-factor authentication to help protect their data.

Read More

Tags: BackdoorBanking TrojanBoliviaChileESETGoogleincidentsIncidents 2023latamMarch 2023MexicoMicrosoftMispaduPeruPortugalTrojanURSA
1
VIEWS
ADVERTISEMENT

Related Posts

Tesla Data Breach: Investigation Underway

Tesla Data Breach: Investigation Underway

May 26, 2023
Del Monte Data Breach Exposes Information

Del Monte Data Breach Exposes Information

May 26, 2023
Marine Corps Data Breach Investigations

Marine Corps Data Breach Investigations

May 26, 2023
Massive Data Breach Exposes VPN Users

Massive Data Breach Exposes VPN Users

May 26, 2023

More Articles

Entertainment

Person of Interest (2011-2016)

November 9, 2020
Incidents

Fishing gear seller caught in hacker’s net

November 9, 2021
Book

Vulnerability Management – Book

November 22, 2021
Certification

Information Systems Security Architecture Professional

February 10, 2022

Security through data

Cybersecurity Domains

  • API Security
  • Business Continuity
  • Career Development
  • Compliance
  • Cryptography
  • HSM
  • KPIs / KRIs
  • Penetration Testing
  • Shift Left
  • Vulnerability Scan

Emerging Technologies

  • 5G
  • Artificial Intelligence
  • Blockchain
  • Cryptocurrency
  • Deepfake
  • E-Commerce
  • Healthcare
  • IoT
  • Quantum Computing

Frameworks

  • CIS Controls
  • CCPA
  • GDPR
  • NIST
  • 23 NYCRR 500
  • HIPAA

Repository

  • Books
  • Certifications
  • Definitions
  • Documents
  • Entertainment
  • Quotes
  • Reports

Threats

  • APTs
  • DDoS
  • Insider Threat
  • Malware
  • Phishing
  • Ransomware
  • Social Engineering

© 2023 | CyberMaterial | All rights reserved.

World’s #1 Cybersecurity Repository

  • About
  • Legal and Privacy Policy
  • Site Map
No Result
View All Result
  • Audience
    • Cyber Citizens
    • Cyber Professionals
    • Institutions
  • Highlights
    • Blog
    • CyberDecoded
    • Cyber Review
    • CyberStory
    • CyberTips
  • Cyber Risks
    • Alerts
    • Attackers
    • Domains
    • Incidents
    • Threats
  • Opportunities
    • Events
    • Jobs
  • Repository
    • Books
    • Certifications
    • Cheat Sheets
    • Courses
    • Definitions
    • Frameworks
    • Games
    • Hardware Tools
    • Memes
    • Movies
    • Papers
    • Podcasts
    • Quotes
    • Reports
  • Report Cyber Incident
  • GET HELP

Subscribe to our newsletter

© 2022 Cybermaterial - Security Through Data .

Welcome Back!

Sign In with Google
Sign In with Linked In
OR

Forgotten Password? Sign Up

Create New Account!

Sign Up with Google
Sign Up with Linked In
OR

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.