Mispadu
MITRE ATT&CK: S1122 View on attack.mitre.org
Aliases: URSA, Mispadu
- First seen
- 2019-01-01 00:00:00
- Malware type
- trojan
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 62 (11 malicious)
- Last IoC activity
- 2026-08-10 16:48:04
- Profile updated
- 2026-07-07 13:04:57
Targeted industries: financial-services
Targeted regions: country_code:br country_code:mx
Context
Mispadu is a banking trojan written in Delphi that was first observed in 2019 and uses a Malware-as-a-Service (MaaS) business model. This malware is operated, managed, and sold by the Malteiro cybercriminal group. Mispadu has mainly been used to target victims in Brazil and Mexico, and has also had confirmed operations throughout Latin America and Europe.
Recent IoC activity
11 malicious indicators in Maltiverse are attributed to Mispadu (S1122). The 11 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| IP address | 54.36.116.0 | 2026-08-10 | 2 |
| file sample | 21062026_1506_Factura_N20260619-133003.lnk.zip | 2026-08-02 | 1 |
| file sample | #Archivo_file_mjtWBsbFUmtUIbZRdUpCdvs_30072026034637.hta | 2026-07-30 | 2 |
| file sample | #Archivo_file_29072026115728.zip | 2026-07-29 | 1 |
| URL | http://a.parcel.beauty/w/c1/ | 2026-07-10 | 1 |
| file sample | 07072026_0316_archivos-20260702-174516.hta.zip | 2026-07-10 | 1 |
| file sample | doc-20260627-207729.zip | 2026-06-29 | 1 |
| file sample | Factura_N20260619-121414.zip | 2026-06-19 | 1 |
| file sample | archivos-20260605-208193.hta | 2026-06-05 | 1 |
| file sample | SNRF931199.zip | 2026-03-06 | 1 |
| URL | http://contadcom.pro/w/c1/ | 2025-05-01 | 1 |
Detection coverage
- 286 Sigma rules
Malware & tools used
- Deobfuscate/Decode Files or Information (attack-pattern)
- Credentials from Web Browsers (attack-pattern)
- Screen Capture (attack-pattern)
- Msiexec (attack-pattern)
- System Language Discovery (attack-pattern)
- Browser Extensions (attack-pattern)
- Browser Information Discovery (attack-pattern)
- Spearphishing Link (attack-pattern)
- System Information Discovery (attack-pattern)
- Malicious File (attack-pattern)
- Native API (attack-pattern)
- Rundll32 (attack-pattern)
- Keylogging (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Process Injection (attack-pattern)
- Security Software Discovery (attack-pattern)
- GUI Input Capture (attack-pattern)
- Process Discovery (attack-pattern)
- System Checks (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Asymmetric Cryptography (attack-pattern)
- Clipboard Data (attack-pattern)
- Credentials from Password Stores (attack-pattern)
Used by threat actors
- Malteiro (threat-actor)
Reports & references
- blog.scilabs.mx — Cyber Threat Profile Malteiro (report)
- blog.scilabs.mx — Cyber Threat Profile Malteiro (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Mispadu (report)
- seguranca-informatica.pt — Ursa Trojan Is Back With A New Dance (report)
- Trend Micro — Mispadu Banking Trojan Resurfaces (report)
- seguranca-informatica.pt — Threat Analysis The Emergent Ursa Trojan Impacts Many Countries Using A Sophisticated Loader (report)
- perception-point.io — Manipulated Caiman The Sophisticated Snare Of Mexicos Banking Predators Technical Edition (report)
- jmp-esp.org — Ursa Mispadu (report)
- ESET — Mispadu Advertisement Discounted Unhappy Meal (report)
- MITRE ATT&CK — S1122 (report)
- blog.scilabs.mx — Evolution Of Banking Trojan Ursa Mispadu (report)
External references
- mitre-attack — S1122
- ESET Security Mispadu Facebook Ads 2019
- Segurança Informática URSA Sophisticated Loader 2020
- SCILabs Malteiro 2021
- SCILabs URSA/Mispadu Evolution 2023
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy