Home/Threat Actor/Zumanek
Threat Actor

Zumanek

zumanek · brazil · active since 2018-01

Zumanek is a smaller Brazilian-origin banking trojan family operationally tracked by ESET researchers as part of the broader Brazilian-origin banking trojan family ecosystem; Brazilian Portuguese language spam email distribution, banking website overlay attacks against Brazilian banking institutions, keystroke logging, screen capture, and clipboard hijacking for transaction redirection, operational tradecraft consistent with ecosystem baseline.

primary targeting of Brazilian banking customers with selective Latin American expansion.

thin public technical documentation relative to larger families in the ecosystem.

curated for LATAM banking malware ecosystem completeness alongside Banbra, Bizarro, Casbaneiro, Grandoreiro, Guildma/Astaroth, Javali, Melcoz, Mekotio, Amavaldo, Krachulka, and Lokorrito.

brazil confidence: medium 5 aliases
Sigma rules200 YARA rules0 Live IOCs0 CVEs exploited0

Profile

Zumanek is a smaller Brazilian-origin banking trojan family operationally tracked by ESET researchers as part of the broader Brazilian-origin banking trojan family ecosystem. The cluster operates with operational characteristics consistent with the ecosystem baseline, Brazilian Portuguese language spam email distribution, banking website overlay attacks against Brazilian banking institutions, keystroke logging, screen capture, and clipboard hijacking for banking transaction redirection. Zumanek does not display significantly distinctive operational tradecraft beyond the Brazilian-origin banking malware ecosystem baseline.

The cluster is curated for LATAM banking malware ecosystem completeness as part of the broader Brazilian-origin banking trojan family panorama in this corpus.

Aliases

5
zumanekzumanek operatorszumanek banking trojanzumanek clusterzumanek_brazilian_banking_cluster

Notable Campaigns

1
2019-2024ESET Zumanek Banking Trojan Tracking and Documentation

Attribution & Reporting

Attributed by
ESETKasperskyBrazilian Federal Police (Policia Federal)Trend Micro
Key reporting
reportESET WeLiveSecurity: Zumanek Banking Trojan Analysis
reportESET WeLiveSecurity: Brazilian Banking Trojan Family Evolution Series
reportKaspersky Securelist: Brazilian Banking Trojan Ecosystem Coverage
reportMalpedia Malware Profile: Zumanek

Operational

State sponsor

Cybercriminal cluster of Brazilian-origin operators responsible for developing, distributing, and operating the Zumanek banking trojan family, a Brazilian-origin banking malware family operating within the broader Brazilian-origin banking trojan ecosystem. The cluster was tracked by ESET researchers and adjacent industry analysis as part of the broader ESET-led research initiative cataloguing Brazilian-origin banking trojan families. Zumanek represents one of the smaller and operationally- thinner-documented families in the broader Brazilian- origin banking malware ecosystem, operationally distinct from but operating in parallel with the more operationally- significant families curated separately in this corpus including Banbra (banbra.yaml, foundational), Bizarro (bizarro.yaml, European expansion), Casbaneiro (casbaneiro.yaml), Grandoreiro (grandoreiro.yaml), Guildma / Astaroth (guildma_astaroth.yaml), Javali (javali.yaml), Melcoz (melcoz.yaml), Mekotio (mekotio.yaml), Amavaldo (amavaldo.yaml), Krachulka (krachulka.yaml), and Lokorrito (lokorrito.yaml).

Industry analysis (ESET, Kaspersky, Brazilian Federal Police investigative reporting) has assessed the cluster as Brazilian-origin based on operational tradecraft characteristics, Brazilian Portuguese language strings in malware samples, and operational targeting profile. The cluster operators have not been individually indicted or publicly named. The cluster operates as a financially-motivated cybercriminal operation with no known state sponsorship.

Motivations
financial_gain, banking_credential_theft, banking_fraud_operations, brazilian_retail_banking_targeting
Sectors
Regions

Detection Blind Spots

51 techniques
Across this actor’s 51 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)47/51 · 92%
Analytics (MITRE CAR)17/51 · 33%
Runtime / container (Falco)7/51 · 13%
File / malware (YARA)1/51 · 1%
Network (Suricata/Snort)14/51 · 27%
Vuln scan (Nuclei)0/51 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

0 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
SPAM EMAIL DISTRIBUTION KITS
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin