logo

Mispadu Trojan Targets Europe, Thousands of Credentials Compromised

ID: b80d8837-4a2a-52ff-83a1-43534544c85a

STIX ID: report--b80d8837-4a2a-52ff-83a1-43534544c85a

Feed Name: The Hacker News

Threat Score
72/100

Date Published: 2024-04-03

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

**Mispadu (URSA) banking trojan campaign expanding beyond LATAM:** Research shows Mispadu — a Delphi-based info-stealer capable of credential theft, screenshots, and keystroke capture — has broadened targeting to Italy, Poland, and Sweden while still primarily impacting Mexico; the multi-stage infection chain (PDF→ZIP→MSI/HTA→VBScript→AutoIT→memory-injected payload) leverages social engineering, anti-VM checks, and historically abused a patched SmartScreen bypass (CVE-2023-36025), uses separate C2 servers for payload delivery and exfiltration, and has resulted in thousands of stolen credentials. The report also notes unrelated but concurrent stealers being distributed via YouTube video descriptions linking to password-protected archives (Lumma, Stealc, Vidar) and references other malware activity observed in the wild.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.