Home/Threat Actor/Numando
Threat Actor

Numando

numando · latin_america_brazilian_organized_cybercrime · active since 2018

Numando (canonical ESET naming per September 2021 "Count once, code twice" disclosure) is a Brazilian- origin banking trojan + ESET Dirty Dozen LATAM banking trojan member active since at least 2018 with signature distinctive YouTube + Pastebin encrypted remote configuration + BMP decoy bundling tradecraft + non-Delphi injector uniqueness identifying tradecraft.

Brazilian-origin organized cybercrime attribution via ESET canonical September 2021 first documentation + ESET Dirty Dozen canonical December 15, 2021 retrospective listing Numando as one of 9 actively covered LATAM banking trojans + The Hacker News canonical September 20, 2021 industry coverage with ESET technical analysis quoting + Threatpost canonical October 2020 LatAm Banking Trojans coverage.

standalone malware platform cluster paralleling amavaldo + ousaban + vadokrist in v0.1.142 LATAM banking trojan operators cell expansion.

operational target profile Brazil almost-exclusive primary target per ESET ("Numando brings interesting new techniques to the pool of Latin American banking trojans' tricks, like using seemingly useless ZIP archives or bundling payloads with decoy BMP images. Geographically, it focuses almost exclusively on Brazil with rare campaigns in Mexico and Spain") + Mexico + Spain rare campaign targets + Portuguese-speaking countries focus; operational attack architecture: (1) MSI installer delivery typical LATAM banking trojan delivery method.

(2) fake banking overlay windows credential capture typical LATAM banking trojan tradecraft + backdoor functionality + screenshots + mouse/keyboard simulation + keystroke capture.

(3) cluster-defining YouTube + Pastebin encrypted remote configuration tradecraft per ESET, YouTube video titles + descriptions used to store remote configuration including C2 server IP + Pastebin storage (cluster-cell coherent with v0.1.133 guildma_astaroth.yaml + v0.1.139 javali.yaml YouTube C2 abuse patterns establishing shared LATAM tradecraft lineage)

(4) cluster-defining decoy BMP image bundled payload steganography tradecraft per ESET , "suspiciously large but valid BMP image file from which the injector extracts and executes the Numando banking trojan", distinctive steganography signature; (5) seemingly useless ZIP archives signature distinctive distribution tradecraft.

(6) cluster- defining non-Delphi injector uniqueness identifying signature per ESET, "the only LATAM banking trojan written in Delphi that uses a non-Delphi injector and its remote configuration format is unique, making two reliable factors when identifying this malware family", distinguishing operator tradecraft within LATAM banking trojan ecosystem; (7) Delphi programming language origin signature typical LATAM banking trojan codebase.

(8) backdoor functionality with fake overlay windows + MSI installer execution chain.

cluster fills the ESET- Dirty-Dozen + YouTube-Pastebin-encrypted-config + BMP-decoy-bundling-steganography + non-Delphi- injector-uniqueness position in Latin American banking trojan operators cell.

canonical illustration of ESET Dirty Dozen LATAM banking trojan + YouTube + Pastebin remote configuration tradecraft + BMP decoy bundling steganography + non-Delphi injector uniqueness identifying signature cited in essentially all subsequent Latin American banking trojan industry analyses through 2018-2026 period.

latin_america_brazilian_organized_cybercrime confidence: high 7 aliases
Sigma rules200 YARA rules0 Live IOCs0 CVEs exploited0

Profile

Numando (canonical ESET naming per September 2021 "Count once, code twice" disclosure) is a Brazilian- origin banking trojan + ESET Dirty Dozen LATAM banking trojan member active since at least 2018 with signature distinctive YouTube + Pastebin encrypted remote configuration + BMP decoy bundling tradecraft + non-Delphi injector uniqueness identifying tradecraft. Brazilian-origin organized cybercrime attribution via ESET canonical September 2021 first documentation + ESET Dirty Dozen canonical December 2021 retrospective + The Hacker News canonical industry coverage. Standalone malware platform cluster paralleling amavaldo + ousaban + vadokrist in v0.1.142 LATAM banking trojan operators cell expansion.

Operational target profile
  • Brazil almost-exclusive primary target per ESET.
  • Mexico + Spain rare campaign targets per ESET.
  • Banking + financial institutions per ESET.
  • Portuguese-speaking countries focus Operational attack architecture: (1) MSI installer delivery (signature): typical LATAM banking trojan delivery method (2) Fake banking overlay windows credential capture (signature): typical LATAM banking trojan tradecraft (3) YouTube + Pastebin encrypted remote configuration (cluster-defining): per ESET, YouTube video titles + descriptions + Pastebin used to store remote configuration including C2 server IP (4) Decoy BMP image bundled payload (cluster- defining): per ESET, "suspiciously large but valid BMP image file from which the injector extracts and executes the Numando banking trojan", distinctive steganography signature (5) Seemingly useless ZIP archives (signature): per ESET, distinctive distribution tradecraft (6) Non-Delphi injector uniqueness (cluster- defining): per ESET, "the only LATAM banking trojan written in Delphi that uses a non-Delphi injector" + "remote configuration format is unique" , two reliable identifier signatures (7) Delphi programming language origin (signature): typical LATAM banking trojan codebase (8) Backdoor functionality + mouse/keyboard simulation (signature) The cluster fills the ESET-Dirty-Dozen + YouTube- Pastebin-encrypted-config + BMP-decoy-bundling + non-Delphi-injector-uniqueness position in the Latin American banking trojan operators cell.

Aliases

7
numandonumando_banking_trojannumando_malwarenumando eset dirty dozen count once code twicenumando brazil banking trojannumando youtube pastebin remote configurationnumando bmp image decoy payload signature

Notable Campaigns

6
2021ESET Canonical First Disclosure (September 2021)
2018-2026Continued Industry Reference Status (2018-2026)
2018-2021Numando YouTube + Pastebin Remote Configuration Signature
2018-2021Numando BMP Decoy Bundling Signature
2018-2021Numando Non-Delphi Injector Uniqueness Signature
2018Numando Origin, Brazil Active Since 2018

Attribution & Reporting

Key reporting
reportESET WeLiveSecurity: Numando, Count once, code twice (September 2021), canonical first documentation
reportThe Hacker News: Numando, A New Banking Trojan Targeting Latin American Users (September 20, 2021), canonical industry coverage with ESET technical analysis
reportESET WeLiveSecurity: The Dirty Dozen of Latin America, From Amavaldo to Zumanek (December 15, 2021), canonical retrospective
reportThreatpost: LatAm Banking Trojans Collaborate (October 2020)
reportESET Research Team: canonical Latin American banking trojan white paper
reportMalpedia Software Profile: Numando

Operational

State sponsor

Brazilian-origin organized cybercrime, ESET Dirty Dozen LATAM banking trojan member, active since at least 2018. Operationally separate from state- sponsored APT activity. Attribution chain: (1) ESET canonical September 2021 first documentation: ESET WeLiveSecurity published "Numando: Count once, code twice" canonical Dirty Dozen entry.

Per The Hacker News reporting: "A newly spotted banking trojan has been caught leveraging legitimate platforms like YouTube and Pastebin to store its encrypted, remote configuration and commandeer infected Windows systems, making it the latest to join the long list of malware targeting Latin America (LATAM) after Guildma, Javali, Melcoz, Grandoreiro, Mekotio, Casbaneiro, Amavaldo, Vadokrist, and Janeleiro. The threat actor behind this malware family, dubbed 'Numando', is believed to have been active since at least 2018." (2) ESET canonical Brazil-focus identification: per ESET via The Hacker News: "Geographically, it focuses almost exclusively on Brazil with rare campaigns in Mexico and Spain." (3) ESET canonical unique-non-Delphi-injector identification: per ESET via The Hacker News: "It is the only LATAM banking trojan written in Delphi that uses a non-Delphi injector and its remote configuration format is unique, making two reliable factors when identifying this malware family." Operationally significant cluster-defining distinctive signature tradecraft. (4) ESET Dirty Dozen canonical December 15, 2021 retrospective: per ESET WeLiveSecurity Dirty Dozen retrospective, Numando listed as one of 9 actively covered LATAM banking trojans (Amavaldo + Casbaneiro + Mispadu + Guildma + Grandoreiro + Mekotio + Vadokrist + Ousaban + Numando).

(5) Threatpost canonical October 2020 industry coverage: per Threatpost: "Multiple, distinct malware families have plagued Latin American banking customers for years
  • the variants include Amavaldo, Casbaneiro, Grandoreiro, Guildma, Krachulka, Lokorrito, Mekotio, Mispadu, Numando, Vadokrist and Zumanek, according to ESET." Operational mission objective: Banking credential theft via fake pop-up overlay tradecraft + backdoor functionality + MSI installer delivery. Typical LATAM banking trojan operational pattern with distinctive YouTube + Pastebin remote configuration + BMP decoy bundling tradecraft.
Operational target profile
  • Brazil almost-exclusive primary target per ESET.
  • Mexico + Spain rare campaign targets per ESET.
  • Banking + financial institutions per ESET.
  • Portuguese-speaking countries focus The cluster fills the ESET-Dirty-Dozen + YouTube- Pastebin-encrypted-config + BMP-decoy-bundling + non-Delphi-injector-uniqueness position in the Latin American banking trojan operators cell.
Motivations
banking_credential_theft_brazil_almost_exclusive_targeting, eset_dirty_dozen_canonical_entry_status, youtube_pastebin_encrypted_remote_configuration_tradecraft, decoy_bmp_image_bundled_payload_signature_tradecraft, non_delphi_injector_uniqueness_per_eset_signature, seemingly_useless_zip_archives_signature_tradecraft
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)59/60 · 98%
Analytics (MITRE CAR)25/60 · 41%
Runtime / container (Falco)7/60 · 11%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)16/60 · 26%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

0 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MSI INSTALLER DELIVERY TYPICAL LATAMSEEMINGLY USELESS ZIP ARCHIVES SIGNATURESUSPICIOUSLY LARGE VALID BMP FILE INJECTOR PAYLOAD EXTRACTION
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin