logo

Mispadu Stealer’s New Variant Targets Browser Data of Mexican Users

ID: 5bfa6f59-fd96-5446-bf6c-f93223602152

STIX ID: report--5bfa6f59-fd96-5446-bf6c-f93223602152

Feed Name: HackRead

Threat Score
70/100

Date Published: 2024-02-02

Date Updated: 2026-04-22

Author: Waqas

...
...

Unit 42 researchers uncovered a new Mispadu Stealer variant that targets Mexican users by exploiting a Windows SmartScreen bypass (CVE-2023-36025). The malware uses crafted .url shortcut files pointing to a threat actor network share to retrieve payloads without triggering SmartScreen, performs timezone-based geofencing to limit execution to specific regions, and exfiltrates browser data while using encryption to evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.