Malteiro
MITRE ATT&CK: G1026 View on attack.mitre.org
Aliases: Malteiro
- First seen
- 2019-11-01 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- intermediate
- Resource level
- organization
- Actor type
- criminal
- Profile updated
- 2026-07-07 12:03:38
Targeted industries: financial-services
Targeted regions: country_code:mx country_code:es country_code:pt
Context
Malteiro is a financially motivated criminal group that is likely based in Brazil and has been active since at least November 2019. The group operates and distributes the Mispadu banking trojan via a Malware-as-a-Service (MaaS) business model. Malteiro mainly targets victims throughout Latin America (particularly Mexico) and Europe (particularly Spain and Portugal).
Detection coverage
- 144 Sigma rules
Malware & tools used
- Credentials from Web Browsers (attack-pattern)
- Dynamic-link Library Injection (attack-pattern)
- Financial Theft (attack-pattern)
- System Information Discovery (attack-pattern)
- Visual Basic (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Security Software Discovery (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Credentials from Password Stores (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- System Language Discovery (attack-pattern)
- Malicious File (attack-pattern)
- Mispadu (malware)
Reports & references
- blog.scilabs.mx — Cyber Threat Profile Malteiro (report)
- blog.scilabs.mx — Cyber Threat Profile Malteiro (report)
- MITRE ATT&CK — G1026 (report)