The Mispadu trojan has expanded outside of Latin America and other Spanish-speaking countries, now targeting users in Italy, Poland, and Sweden.

The targets of the persistent campaign include entities operating in the finance, services, motor vehicle manufacturing, law firms and commercial establishments sectors, according to Morphisec.
“Despite its large geographical area, Mexico remains a prime target,” security researcher Arnold Osipov said in a report published last week.
Read more: Mispadu banking trojan: Exploits Windows SmartScreen vulnerability
The campaign resulted in the theft of thousands of credentials, with records dating back to April 2023. The threat actor exploits these credentials to craft malicious phishing messages, posing a serious threat to recipients.
The Mispadu trojan, also known as URSA, emerged in 2019 after being observed carrying out credential theft activities targeting financial institutions in Brazil and Mexico. The Delphi-based malware is also capable of taking screenshots and recording keystrokes.
Attack networks have recently exploited a now-patched security vulnerability in Windows SmartScreen (CVE-2023-36025, CVSS score: 8.8) to attack users in Mexico
The infection sequence analyzed by Morphisec is a multi-stage process that begins with a PDF attachment in emails with the subject line “invoice.” When the PDF is opened, the recipient is prompted to click on a malicious link to download the “invoice,” resulting in the download of a ZIP file.
The ZIP file comes with either an MSI installer or an HTA script that is responsible for retrieving and executing a set of Visual Basic (VBScript) actions from a remote server. The server, after downloading a second VBScript, finally downloads and launches the Mispadu payload, using an AutoIT script.
"This second scenario is unclear and uses the same decryption algorithm mentioned in the DLL," according to Osipov.
“Before proceeding to download and execute the next stage, the script performs multiple Anti-VM checks. These checks include the computer’s model, manufacturer, and BIOS version and are compared to those associated with virtual machines.”
Mispadu attacks are also characterized by the use of two separate command and control (C2) servers. One is used to recover the payloads in the mid- and final stages of the attack, while the other is used to retrieve stolen credentials from over 200 services. Currently, there are over 60,000 files on the server.
The DFIR report details an attack that occurred in February 2023. This included the malicious use of Microsoft OneNote to target IcedID, as well as its use to target Cobalt Strike, AnyDesk, and the Nokoyawa ransomware.
A year ago, Microsoft announced its plan to block 120 extensions embedded in OneNote files, in order to prevent them from being misused to spread malware.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Security firm Proofpoint also reported that many YouTube channels promoting cracked and pirated video games act as a conduit for providing information thefts such as Lumma Stealer, Stealc, and Vidar by adding malicious links to video descriptions.
“The videos pretend to show the user how to perform various tasks, such as downloading software or upgrading video games for free. However, the links in the video descriptions lead to malware,” said security researcher Isaac Shaughnessy.

There are indications that such videos are being posted by hacked accounts, but there is also the possibility that those behind the operation may have created temporary accounts to spread the videos.
All videos contain URLs for Discord and MediaFire, which point to password-. This results in the development of malware.
See also: PixPirate banking trojan targets users in Brazil
Proofpoint announced that it detected multiple malicious activities via YouTube.
“The techniques used are similar, including using video descriptions to encrypt URLs to redirect to malware and provide instructions to disable antivirus software, as well as using large compressed files to avoid detection,” according to Shaughnessy.
Source: thehackernews
