Mispadu

MITRE ATT&CK: S1122 View on attack.mitre.org

Aliases: URSA, Mispadu

First seen
2019-01-01 00:00:00
Malware type
trojan
Family
Malware family
Operating systems
windows
Related IoCs
62 (11 malicious)
Last IoC activity
2026-08-10 16:48:04
Profile updated
2026-07-07 13:04:57

Targeted industries: financial-services

Targeted regions: country_code:br country_code:mx

Context

Mispadu is a banking trojan written in Delphi that was first observed in 2019 and uses a Malware-as-a-Service (MaaS) business model. This malware is operated, managed, and sold by the Malteiro cybercriminal group. Mispadu has mainly been used to target victims in Brazil and Mexico, and has also had confirmed operations throughout Latin America and Europe.

Recent IoC activity

11 malicious indicators in Maltiverse are attributed to Mispadu (S1122). The 11 most recently updated:

TypeIndicatorUpdatedSources
IP address 54.36.116.0 2026-08-10 2
file sample 21062026_1506_Factura_N20260619-133003.lnk.zip 2026-08-02 1
file sample #Archivo_file_mjtWBsbFUmtUIbZRdUpCdvs_30072026034637.hta 2026-07-30 2
file sample #Archivo_file_29072026115728.zip 2026-07-29 1
URL http://a.parcel.beauty/w/c1/ 2026-07-10 1
file sample 07072026_0316_archivos-20260702-174516.hta.zip 2026-07-10 1
file sample doc-20260627-207729.zip 2026-06-29 1
file sample Factura_N20260619-121414.zip 2026-06-19 1
file sample archivos-20260605-208193.hta 2026-06-05 1
file sample SNRF931199.zip 2026-03-06 1
URL http://contadcom.pro/w/c1/ 2025-05-01 1

Detection coverage

  • 286 Sigma rules

Malware & tools used

  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Credentials from Web Browsers (attack-pattern)
  • Screen Capture (attack-pattern)
  • Msiexec (attack-pattern)
  • System Language Discovery (attack-pattern)
  • Browser Extensions (attack-pattern)
  • Browser Information Discovery (attack-pattern)
  • Spearphishing Link (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Malicious File (attack-pattern)
  • Native API (attack-pattern)
  • Rundll32 (attack-pattern)
  • Keylogging (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Process Injection (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • GUI Input Capture (attack-pattern)
  • Process Discovery (attack-pattern)
  • System Checks (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Asymmetric Cryptography (attack-pattern)
  • Clipboard Data (attack-pattern)
  • Credentials from Password Stores (attack-pattern)

Used by threat actors

Reports & references

  • blog.scilabs.mx — Cyber Threat Profile Malteiro (report)
  • blog.scilabs.mx — Cyber Threat Profile Malteiro (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Mispadu (report)
  • seguranca-informatica.pt — Ursa Trojan Is Back With A New Dance (report)
  • Trend Micro — Mispadu Banking Trojan Resurfaces (report)
  • seguranca-informatica.pt — Threat Analysis The Emergent Ursa Trojan Impacts Many Countries Using A Sophisticated Loader (report)
  • perception-point.io — Manipulated Caiman The Sophisticated Snare Of Mexicos Banking Predators Technical Edition (report)
  • jmp-esp.org — Ursa Mispadu (report)
  • ESET — Mispadu Advertisement Discounted Unhappy Meal (report)
  • MITRE ATT&CK — S1122 (report)
  • blog.scilabs.mx — Evolution Of Banking Trojan Ursa Mispadu (report)

External references