Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 16:37:57 UTC Home > List all groups > List all tools > List all groups using tool Numando Tool: Numando Names Numando Category Malware Type Banking trojan, Reconnaissance, Backdoor, Keylogger, Info stealer, Credential stealer Description (ESET) The threat actor behind this malware family has been active since at least 2018. Even though it is not nearly as lively as Mekotio or Grandoreiro, it has been consistently used since we started tracking it, bringing interesting new techniques to the pool of Latin American banking trojans’ tricks, like using seemingly useless ZIP archives or bundling payloads with decoy BMP images. Geographically, it focuses almost exclusively on Brazil with rare campaigns in Mexico and Spain. Information Malpedia Last change to this tool card: 28 December 2021 Download this tool card in JSON format All groups using tool Numando Changed Name Country Observed Unknown groups _[ Interesting malware not linked to an actor yet ]_ 1 group listed (0 APT, 0 other, 1 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=69a2b688-207b-49f4-a1f8-8ac568b6eca9 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=69a2b688-207b-49f4-a1f8-8ac568b6eca9 Page 1 of 1