Malteiro is a financially motivated criminal group that is likely based in Brazil and has been active since at least November 2019. The group operates and distributes the Mispadu banking trojan via a Malware-as-a-Service (MaaS) business model. Malteiro mainly targets victims throughout Latin America (particularly Mexico) and Europe (particularly Spain and Portugal).(Citation: SCILabs Malteiro 2021)
Executive Summary
Malteiro is a financially motivated crime group operating out of Brazil, active since at least November 2019, with a focus on distributing the Mispadu banking trojan through a Malware-as-a-Service (MaaS) model. They primarily target victims in Latin America and Europe. Their operations pose a significant threat to financial institutions and individuals in these regions.
Goals & Targeting
Malteiro's strategic objectives are centered around financial gain, primarily through the theft of banking and financial information. They target specific sectors such as banking and financial institutions in Latin America and Europe, aiming to exploit vulnerabilities and capitalize on the wealth present in these regions. Their typical victims include individuals and businesses with considerable financial assets, whom they target through sophisticated social engineering tactics and the deployment of the Mispadu trojan.
Enhanced Description
The threat posed by Malteiro is significant, given the financial motivation and the broad geographic range of their targets. Their ability to operate undetected for extended periods and their capacity to adjust their tactics, techniques, and procedures (TTPs) suggest a level of sophistication that demands constant vigilance from potential victims and the cybersecurity community at large. The use of the Mispadu trojan under a MaaS model allows for rapid deployment and potentially high returns, making Malteiro a formidable opponent in the cybercrime landscape.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Malteiro's campaign patterns are characterized by a high level of adaptability and the strategic use of the Mispadu trojan to target financial institutions and individuals in Latin America and Europe. Their operational tempo suggests a well-organized and planned approach, with the potential for rapid scaling of their operations. Notable past operations have included targeted phishing campaigns and the exploitation of vulnerabilities in banking software, indicating a preference for exploiting human factors and technical vulnerabilities.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence level in the available data on Malteiro is moderate, with some information gaps existing regarding their exact organizational structure, full range of technical capabilities, and the scope of their operations beyond Latin America and Europe. Further research and monitoring are necessary to fully understand the threat posed by this group.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
12
Techniques
1
Tools
0
Campaigns
0
IOCs
0
Observed Data
6
Tactics