ESET has identified yet another family of malware, named Mispadu, as part of its research into banking Trojans in Latin America.
Mispadu's code is written in Delphi, like the Amavaldo and Casbaneiro malware families, and uses fake pop-ups to target users, trying to trick them into sharing their personal information and credentials. The Mispadu banking trojan, responsible for attacks primarily in Brazil and Mexico, contains backdoor, can take screenshots, simulate mouse and keyboard actions, and record keystrokes.
ESET's research team discovered that the Mispadu family uses two different distribution methods: spam and malvertising. While the former is common among Latin American banking Trojans, the latter is quite rare. The operator of Mispadu places sponsored ads on Facebook, offering fake discount coupons for McDonald's.

By clicking on the ad, the potential victim is taken to a malicious website, where they can download a ZIP file with an MSI installer, which appears as a discount coupon. If downloaded and executed, a chain of three scenarios follows, leading to the download and execution of Mispadu.
The trojan uses four potentially unwanted applications, all modified copies of genuine software, to extract the victim's stored credentials from browsers and email programs.
In Brazil, Mispadu is also distributing an interesting, malicious Google Chrome extension. The extension claims to “Protect Chrome,” but in reality it tries to steal credit card and online banking data. It can even compromise Boleto, a popular payment method in Brazil that uses a barcode ticketing system to transfer funds.
The Boleto feature is the most advanced feature in Mispadu's attacks, as it replaces the original barcode on the Boleto ticket with another barcode, created through the misuse of a legitimate website, that leads to the attacker's bank account.
More details in the article "Mispadu: advertisement for a discounted Unhappy Meal", on WeLiveSecurity.
