Mispadu, a supposedly banking trojan and infostealer that targets LATAM has evolved itself and now venturing not just in that region but other European as well and it also includes crypto exchanges in their crosshair.
Sample phishing email sent by the threat actor, which include a PDF attachment that contains the malware as it will download a ZIP file through a URL shortener service.
Below are the target crypto exchanges,
And this is the two Bitcoin addresses associated with the cyber criminals,
- bc1qn5fwarp0wesjahyaavj3zpzawsh3mp0mpuw94n
- bc1qzcdrhp30eztexrmyvz5dwuyzzqyylq5muuyllf
The first address has close to 1
BTC already.
This address has transacted 62 times on the Bitcoin blockchain. It has received a total of 0.82939740 BTC $55,022.77 and has sent a total of 0.82937010 BTC $55,020.96 The current value of this address is 0.00002730 BTC $1.81.
https://blog.morphisec.com/mispadu-infiltration-beyond-latam