AdversaryGraph public intelligence page
This page is part of Threat Matrix, the public browser workspace for the main AdversaryGraph platform. Use it for ATT&CK pivots, actor and technique context, similarity leads, detection coverage review, and analyst-ready investigation paths.
Validation disclaimer: TTP overlap, actor similarity, generated summaries, and coverage findings are investigation leads, not attribution proof or operational validation without analyst review.
Main AdversaryGraph project Documentation Malware Analysis GitHub
Malteiro
Aliases: None listed
Malteiro is a financially motivated criminal group that is likely based in Brazil and has been active since at least November 2019. The group operates and distributes the Mispadu banking trojan via a Malware-as-a-Service (MaaS) business model. Malteiro mainly targets victims throughout Latin America (particularly Mexico) and Europe (particularly Spain and Portugal).
Open interactive actor investigation
ATT&CK techniques
Malicious FileT1555.003
Credentials from Web BrowsersT1055.001
Dynamic-link Library InjectionT1657
Financial TheftT1082
System Information DiscoveryT1059.005
Visual BasicT1027.013
Encrypted/Encoded FileT1518.001
Security Software DiscoveryT1566.001
Spearphishing AttachmentT1555
Credentials from Password StoresT1140
Deobfuscate/Decode Files or InformationT1614.001
System Language Discovery
Correlated CTI and IR reports
Continue the investigation
Cyber Knowledge routes
These contextual routes explain behaviors associated with this ATT&CK group record. They support learning and investigation planning; they do not add attribution evidence.
OSINT & Reconnaissance · topic-matchCryptography, secrets, and key lifecycle
Secure Code & Application Security · topic-matchPrivacy, secrets, confidential data, and model leakage
AI Security · topic-matchAI-assisted analysis, RAG/MCP controls, and defensive handoff
Malware Analysis & Reverse Engineering · topic-matchSecure AI development lifecycle and production release gate
AI Security · topic-matchAI-generated code, RAG, models, agents, and MCP-connected tools
Secure Code & Application Security · topic-matchAI incident response and forensic readiness
AI Security · topic-matchModule 6 — Alert triage, investigation, and escalation
Blue Team & Defensive Security · topic-matchThreat modeling and secure architecture
Secure Code & Application Security · topic-matchDynamic analysis, debugging, and tracing
Vulnerability Research & Exploit Development · topic-matchMemory forensics and runtime reconstruction
Digital Forensics & Incident Response (DFIR) · topic-matchAgents, tools, plugins, browsers, and MCP security
AI Security · topic-match