Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Malteiro

Description

Malteiro is a financially motivated criminal group that is likely based in Brazil and has been active since at least November 2019. The group operates and distributes the Mispadu banking trojan via a Malware-as-a-Service (MaaS) business model. Malteiro mainly targets victims throughout Latin America (particularly Mexico) and Europe (particularly Spain and Portugal).(Citation: SCILabs Malteiro 2021)

AI Analysis

· 2 months ago

Executive Summary

Malteiro is a financially motivated crime group operating out of Brazil, active since at least November 2019, with a focus on distributing the Mispadu banking trojan through a Malware-as-a-Service (MaaS) model. They primarily target victims in Latin America and Europe. Their operations pose a significant threat to financial institutions and individuals in these regions.

Goals & Targeting

Malteiro's strategic objectives are centered around financial gain, primarily through the theft of banking and financial information. They target specific sectors such as banking and financial institutions in Latin America and Europe, aiming to exploit vulnerabilities and capitalize on the wealth present in these regions. Their typical victims include individuals and businesses with considerable financial assets, whom they target through sophisticated social engineering tactics and the deployment of the Mispadu trojan.

Enhanced Description

The threat posed by Malteiro is significant, given the financial motivation and the broad geographic range of their targets. Their ability to operate undetected for extended periods and their capacity to adjust their tactics, techniques, and procedures (TTPs) suggest a level of sophistication that demands constant vigilance from potential victims and the cybersecurity community at large. The use of the Mispadu trojan under a MaaS model allows for rapid deployment and potentially high returns, making Malteiro a formidable opponent in the cybercrime landscape.

Key Capabilities

  • Advanced social engineering tactics
  • Deployment and management of the Mispadu banking trojan
  • Malware-as-a-Service (MaaS) operations
  • Financial data exfiltration and exploitation

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence

ATT&CK Techniques

T1059.003
T1055
T1566.001

Software / Tooling

Mispadu banking trojan

Campaigns & Victims

Malteiro's campaign patterns are characterized by a high level of adaptability and the strategic use of the Mispadu trojan to target financial institutions and individuals in Latin America and Europe. Their operational tempo suggests a well-organized and planned approach, with the potential for rapid scaling of their operations. Notable past operations have included targeted phishing campaigns and the exploitation of vulnerabilities in banking software, indicating a preference for exploiting human factors and technical vulnerabilities.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • Deployment of the Mispadu trojan via exploit kits

Recommended Actions

  • Implement robust email filtering and phishing detection
  • Regularly update and patch banking and financial software
  • Conduct thorough security audits and penetration testing

Suggested Tags

Financially motivated
MaaS
Banking trojan
Latin America
Europe

Confidence Assessment

The confidence level in the available data on Malteiro is moderate, with some information gaps existing regarding their exact organizational structure, full range of technical capabilities, and the scope of their operations beyond Latin America and Europe. Further research and monitoring are necessary to fully understand the threat posed by this group.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. SCILabs Malteiro 2021 — SCILabs. (2021, December 23). Cyber Threat Profile Malteiro. Retrieved March 13, 2024.

Intel Summary

12

Techniques

1

Tools

0

Campaigns

0

IOCs

0

Observed Data

6

Tactics

Tags

Financial Targeting

Details

MITRE ID
G1026
Type
Unknown
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--bf668120-e9a6-4017-a014-bfc0f5232656
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.