NEW: Group Profiler — instant APT intel lookup. Try it →

Malteiro

Overview

Malteiro is a financially motivated criminal group that is likely based in Brazil and has been active since at least November 2019. The group operates and distributes the Mispadu banking trojan via a Malware-as-a-Service (MaaS) business model. Malteiro mainly targets victims throughout Latin America (particularly Mexico) and Europe (particularly Spain and Portugal).

Naming & attribution

Malteiro is tracked under 1 names across the industry. It uses 12 documented ATT&CK techniques — more than 35% of the 174 groups tracked here.

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • Molerats — 5 shared techniques (22% overlap)
  • SideCopy Pakistan — 5 shared techniques (22% overlap)
  • Inception Russia — 6 shared techniques (21% overlap)
  • TA459 China — 3 shared techniques (21% overlap)
  • Darkhotel South Korea — 6 shared techniques (20% overlap)
  • Ajax Security Team Iran — 3 shared techniques (20% overlap)

Malware families with current indicators

One family attributed to Malteiro, carrying 4 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.

  • Mispadu 4 indicators

Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.

TTPs — 12 techniques across 6 tactics

Tools & malware (1)

Mispadu

Reporting (1)