Zumanek
- Malware type
- trojan
- Family
- Malware family
- Profile updated
- 2026-07-07 15:08:48
Targeted regions: country_code:br
Context
According to ESET, this malware family was active exclusively in Brazil until the middle of 2020. It s identified by its method for obfuscating strings. It creates a function for each character of the alphabet and then concatenates the result of calling the correct functions in sequence.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Zumanek_Auto (yara-rule)
Reports & references
- ESET — Dirty Dozen Latin America Amavaldo Zumanek (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Zumanek (report)
- ESET — Zumanek Malware Tenta Roubar Credenciais De Servicos (report)