Malteiro

MITRE ATT&CK: G1026 View on attack.mitre.org

Aliases: Malteiro

First seen
2019-11-01 00:00:00
Primary motivation
financial-gain
Sophistication
intermediate
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 12:03:38

Targeted industries: financial-services

Targeted regions: country_code:mx country_code:es country_code:pt

Context

Malteiro is a financially motivated criminal group that is likely based in Brazil and has been active since at least November 2019. The group operates and distributes the Mispadu banking trojan via a Malware-as-a-Service (MaaS) business model. Malteiro mainly targets victims throughout Latin America (particularly Mexico) and Europe (particularly Spain and Portugal).

Detection coverage

  • 144 Sigma rules

Malware & tools used

  • Credentials from Web Browsers (attack-pattern)
  • Dynamic-link Library Injection (attack-pattern)
  • Financial Theft (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Visual Basic (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Credentials from Password Stores (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • System Language Discovery (attack-pattern)
  • Malicious File (attack-pattern)
  • Mispadu (malware)

Reports & references

  • blog.scilabs.mx — Cyber Threat Profile Malteiro (report)
  • blog.scilabs.mx — Cyber Threat Profile Malteiro (report)
  • MITRE ATT&CK — G1026 (report)

External references