logo

Mispadu Phishing Malware Baseline: Delivery Chains, Capabilities, and Common Campaigns

ID: 1e9d9e14-e785-50e4-80b2-2dfbb2457928

STIX ID: report--1e9d9e14-e785-50e4-80b2-2dfbb2457928

Feed Name: Cofense Blog

Threat Score
75/100

Date Published: 2026-02-11

Date Updated: 2026-04-27

Author: Cofense

...
...

Mispadu is a persistent Latin American–targeted banking trojan active since 2019 and significantly scaled up in 2024–2025; campaigns deliver dynamically generated HTA/JS/VBS chains (often via password‑protected PDFs) that load AutoIT-based loaders and legitimate utilities to steal credentials, inject web content, and self‑propagate via Outlook. Operators use advanced obfuscation, geofencing, dynamic payloads, and legitimate binaries to evade detection, and the activity is tied to a tracked APT group responsible for widespread, ongoing phishing campaigns across Mexico, Brazil and other regions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.