Numando
Numando (canonical ESET naming per September 2021 "Count once, code twice" disclosure) is a Brazilian- origin banking trojan + ESET Dirty Dozen LATAM banking trojan member active since at least 2018 with signature distinctive YouTube + Pastebin encrypted remote configuration + BMP decoy bundling tradecraft + non-Delphi injector uniqueness identifying tradecraft.
Brazilian-origin organized cybercrime attribution via ESET canonical September 2021 first documentation + ESET Dirty Dozen canonical December 15, 2021 retrospective listing Numando as one of 9 actively covered LATAM banking trojans + The Hacker News canonical September 20, 2021 industry coverage with ESET technical analysis quoting + Threatpost canonical October 2020 LatAm Banking Trojans coverage.
standalone malware platform cluster paralleling amavaldo + ousaban + vadokrist in v0.1.142 LATAM banking trojan operators cell expansion.
operational target profile Brazil almost-exclusive primary target per ESET ("Numando brings interesting new techniques to the pool of Latin American banking trojans' tricks, like using seemingly useless ZIP archives or bundling payloads with decoy BMP images. Geographically, it focuses almost exclusively on Brazil with rare campaigns in Mexico and Spain") + Mexico + Spain rare campaign targets + Portuguese-speaking countries focus; operational attack architecture: (1) MSI installer delivery typical LATAM banking trojan delivery method.
(2) fake banking overlay windows credential capture typical LATAM banking trojan tradecraft + backdoor functionality + screenshots + mouse/keyboard simulation + keystroke capture.
(3) cluster-defining YouTube + Pastebin encrypted remote configuration tradecraft per ESET, YouTube video titles + descriptions used to store remote configuration including C2 server IP + Pastebin storage (cluster-cell coherent with v0.1.133 guildma_astaroth.yaml + v0.1.139 javali.yaml YouTube C2 abuse patterns establishing shared LATAM tradecraft lineage)
(4) cluster-defining decoy BMP image bundled payload steganography tradecraft per ESET , "suspiciously large but valid BMP image file from which the injector extracts and executes the Numando banking trojan", distinctive steganography signature; (5) seemingly useless ZIP archives signature distinctive distribution tradecraft.
(6) cluster- defining non-Delphi injector uniqueness identifying signature per ESET, "the only LATAM banking trojan written in Delphi that uses a non-Delphi injector and its remote configuration format is unique, making two reliable factors when identifying this malware family", distinguishing operator tradecraft within LATAM banking trojan ecosystem; (7) Delphi programming language origin signature typical LATAM banking trojan codebase.
(8) backdoor functionality with fake overlay windows + MSI installer execution chain.
cluster fills the ESET- Dirty-Dozen + YouTube-Pastebin-encrypted-config + BMP-decoy-bundling-steganography + non-Delphi- injector-uniqueness position in Latin American banking trojan operators cell.
canonical illustration of ESET Dirty Dozen LATAM banking trojan + YouTube + Pastebin remote configuration tradecraft + BMP decoy bundling steganography + non-Delphi injector uniqueness identifying signature cited in essentially all subsequent Latin American banking trojan industry analyses through 2018-2026 period.