LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0455: Metamorfo

Metamorfo is a Latin-American banking trojan operated by a Brazilian cybercrime group that has been active since at least April 2018. The group focuses on targeting banks and cryptocurrency services in Brazil and Mexico.[1][2]

EnterpriseS0455MalwareObject v2.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Metamorfo matters because ATT&CK describes it as a Windows banking trojan focused on banks and cryptocurrency services in Brazil and Mexico. For leaders, the practical issue is not only malware blocking; the related behaviors include credential and GUI input capture, discovery of users/processes/windows/files, command-and-control, tool transfer, exfiltration over C2, registry modification, DLL injection, and evidence removal. That combination can turn a single infected endpoint into a fraud, credential-theft, and incident-response visibility problem.

Executive priority

Prioritize Metamorfo as a financial-services and digital-asset risk scenario where Windows endpoint visibility, identity protection, fraud response, and SOC/IR readiness intersect. Executives should ask whether endpoints used for banking, treasury, crypto operations, finance administration, or privileged access have sufficient monitoring for credential capture, suspicious scripting, C2 over web-like channels, registry changes, injected processes, and file deletion. The object has no official ATT&CK detection text, so coverage should be proven through local telemetry and control validation rather than assumed from malware signatures alone.

Technical view

ATT&CK lists Metamorfo as Windows malware and relates it to discovery, execution, credential-access/collection, command-and-control, exfiltration, persistence/defense impairment, and stealth techniques. SOC and detection teams should validate behavior-based coverage for Application Window Discovery, System Owner/User Discovery, Process Discovery, System Information Discovery, File and Directory Discovery, Windows Command Shell, Visual Basic, JavaScript, Native API activity, DLL Injection, Keylogging, GUI Input Capture, Modify Registry, Web Protocols C2, Non-Application Layer Protocol C2, Dead Drop Resolver, One-Way Communication, Ingress Tool Transfer, Exfiltration Over C2 Channel, Software Packing, Encrypted/Encoded Files, masquerading by matching legitimate resource names or locations, Indicator Removal, and File Deletion. Because no official detection guidance is provided, detections should be mapped to these related techniques and tested against normal Windows administrative and user activity.

Likely telemetry

  • Windows endpoint process creation and command-line telemetry
  • Script execution telemetry for Windows command shell, Visual Basic, and JavaScript/JScript activity
  • Endpoint file creation, modification, deletion, and packed or encoded file indicators
  • Windows Registry modification events
  • Process injection or DLL load telemetry where available

Detection direction

  • Do not rely only on malware family names or static signatures; ATT&CK relationships show multiple stealth and obfuscation behaviors including packing, encrypted/encoded files, masquerading, and file deletion.
  • Correlate discovery bursts on Windows endpoints with subsequent scripting, registry modification, process injection, external communications, or file transfer activity.
  • Tune command shell, Visual Basic, and JavaScript detections to distinguish normal administration from unusual execution chains, especially when launched from unexpected user contexts or locations.
  • Hunt for suspicious registry changes paired with persistence or defense-impairment context rather than treating all registry activity as equally suspicious.
  • Review web-protocol C2 detections for blind spots involving legitimate external web services, dead drop resolver patterns, and one-way command retrieval.

Mitigation priorities

  • Start with asset and user scoping: identify Windows systems and accounts used for banking, treasury, cryptocurrency services, finance operations, and privileged administration.
  • Harden endpoint prevention and monitoring against suspicious script execution, unauthorized tool transfer, packed or encoded executables, registry modification, and process injection.
  • Restrict and monitor unnecessary scripting and command-shell use where business processes allow, while maintaining exceptions for documented administrative workflows.
  • Strengthen egress controls and proxy/DNS logging for web-protocol communications and access to external services that could be abused for C2 redirection or one-way command retrieval.
  • Use least privilege and identity controls to reduce the value of captured credentials and GUI prompts, particularly for finance and privileged users.
Additional notes and limits

The supplied ATT&CK description identifies Metamorfo as a Latin-American banking trojan operated by a Brazilian cybercrime group, active since at least April 2018, focused on banks and cryptocurrency services in Brazil and Mexico. The strongest defender value comes from the relationship set: it indicates a Windows malware scenario involving discovery, credential/input capture, execution via shell and scripting, C2, exfiltration, registry modification, DLL injection, obfuscation, masquerading, tool transfer, and cleanup behaviors.

ATT&CK provides no official detection text for this object, no aliases, and no object-level tactics. Some related techniques list broad cross-platform applicability, but the malware object itself is supplied as Windows, so local validation should focus on Windows unless separate evidence supports other platforms. This summary does not establish current activity, customer exposure, specific indicators, or guaranteed detection coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Metamorfo

Metamorfo is a Latin-American banking trojan operated by a Brazilian cybercrime group that has been active since at least April 2018. The group focuses on targeting banks and cryptocurrency services in Brazil and Mexico.[1][2]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

46 rows
DomainIDNameRelationship / procedure
EnterpriseT1059.007JavaScriptSub-technique

Metamorfo includes payloads written in JavaScript.[1]

EnterpriseT1518Software Discovery

Metamorfo has searched the compromised system for banking applications.[3][2]

EnterpriseT1056.001KeyloggingSub-technique

Metamorfo has a command to launch a keylogger and capture keystrokes on the victim’s machine.[4][2]

EnterpriseT1518.001Security Software DiscoverySub-technique

Metamorfo collects a list of installed antivirus software from the victim’s system.[4][2]

EnterpriseT1573.002Asymmetric CryptographySub-technique

Metamorfo's C2 communication has been encrypted using OpenSSL.[1]

EnterpriseT1071.001Web ProtocolsSub-technique

Metamorfo has used HTTP for C2.[1][2]

EnterpriseT1218.007MsiexecSub-technique

Metamorfo has used MsiExec.exe to automatically execute files.[4][2]

EnterpriseT1204.002Malicious FileSub-technique

Metamorfo requires the user to double-click the executable to run the malicious HTA file or to download a malicious installer.[3][2]

EnterpriseT1055.001Dynamic-link Library InjectionSub-technique

Metamorfo has injected a malicious DLL into the Windows Media Player process (wmplayer.exe).[1]

EnterpriseT1102.001Dead Drop ResolverSub-technique

Metamorfo has used YouTube to store and hide C&C server domains.[2]

EnterpriseT1027.013Encrypted/Encoded FileSub-technique

Metamorfo has encrypted payloads and strings.[1][2]

EnterpriseT1106Native API

Metamorfo has used native WINAPI calls.[1][4]

EnterpriseT1574.001DLLSub-technique

Metamorfo has side-loaded its malicious DLL file.[1][3][2]

EnterpriseT1566.001Spearphishing AttachmentSub-technique

Metamorfo has been delivered to victims via emails with malicious HTML attachments.[3][2]

EnterpriseT1124System Time Discovery

Metamorfo uses JavaScript to get the system time.[1]

EnterpriseT1095Non-Application Layer Protocol

Metamorfo has used raw TCP for C2.[3]

EnterpriseT1547.001Registry Run Keys / Startup FolderSub-technique

Metamorfo has configured persistence to the Registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run, Spotify =% APPDATA%\Spotify\Spotify.exe and used .LNK files in the startup folder to achieve persistence.[1][3][4][2]

EnterpriseT1041Exfiltration Over C2 Channel

Metamorfo can send the data it collects to the C2 server.[2]

EnterpriseT1070Indicator Removal

Metamorfo has a command to delete a Registry key it uses, \Software\Microsoft\Internet Explorer\notes.[3]

EnterpriseT1056.002GUI Input CaptureSub-technique

Metamorfo has displayed fake forms on top of banking sites to intercept credentials from victims.[3]

EnterpriseT1497Virtualization/Sandbox Evasion

Metamorfo has embedded a "vmdetect.exe" executable to identify virtual machines at the beginning of execution.[1]

EnterpriseT1070.004File DeletionSub-technique

Metamorfo has deleted itself from the system after execution.[1][4]

EnterpriseT1112Modify Registry

Metamorfo has written process names to the Registry, disabled IE browser features, deleted Registry keys, and changed the ExtendedUIHoverTime key.[1][4][3][2]

EnterpriseT1102.003One-Way CommunicationSub-technique

Metamorfo has downloaded a zip file for execution on the system.[1][3][4]

EnterpriseT1119Automated Collection

Metamorfo has automatically collected mouse clicks, continuous screenshots on the machine, and set timers to collect the contents of the clipboard and website browsing.[3]

EnterpriseT1571Non-Standard Port

Metamorfo has communicated with hosts over raw TCP on port 9999.[3]

EnterpriseT1218.005MshtaSub-technique

Metamorfo has used mshta.exe to execute a HTA payload.[3]

EnterpriseT1115Clipboard Data

Metamorfo has a function to hijack data from the clipboard by monitoring the contents of the clipboard and replacing the cryptocurrency wallet with the attacker's.[4][2]

EnterpriseT1129Shared Modules

Metamorfo had used AutoIt to load and execute the DLL payload.[4]

EnterpriseT1082System Information Discovery

Metamorfo has collected the hostname and operating system version from the compromised host.[3][4][2]

EnterpriseT1565.002Transmitted Data ManipulationSub-technique

Metamorfo has a function that can watch the contents of the system clipboard for valid bitcoin addresses, which it then overwrites with the attacker's address.[4][2]

EnterpriseT1113Screen Capture

Metamorfo can collect screenshots of the victim’s machine.[3][2]

EnterpriseT1553.002Code SigningSub-technique

Metamorfo has digitally signed executables using AVAST Software certificates.[1]

EnterpriseT1059.003Windows Command ShellSub-technique

Metamorfo has used cmd.exe /c to execute files.[1]

EnterpriseT1027.002Software PackingSub-technique

Metamorfo has used VMProtect to pack and protect files.[4]

EnterpriseT1685Disable or Modify Tools

Metamorfo has a function to kill processes associated with defenses and can prevent certain processes from launching.[1][3]

EnterpriseT1010Application Window Discovery

Metamorfo can enumerate all windows on the victim’s machine.[3][4]

EnterpriseT1033System Owner/User Discovery

Metamorfo has collected the username from the victim's machine.[2]

EnterpriseT1036.005Match Legitimate Resource Name or LocationSub-technique

Metamorfo has disguised an MSI file as the Adobe Acrobat Reader Installer and has masqueraded payloads as OneDrive, WhatsApp, or Spotify, for example.[1][2]

EnterpriseT1105Ingress Tool Transfer

Metamorfo has used MSI files to download additional files to execute.[1][3][4][2]

EnterpriseT1057Process Discovery

Metamorfo has performed process name checks and has monitored applications.[1]

EnterpriseT1573.001Symmetric CryptographySub-technique

Metamorfo has encrypted C2 commands with AES-256.[2]

EnterpriseT1059.005Visual BasicSub-technique

Metamorfo has used VBS code on victims’ systems.[3]

EnterpriseT1564.003Hidden WindowSub-technique

Metamorfo has hidden its GUI using the ShowWindow() WINAPI call.[1]

EnterpriseT1140Deobfuscate/Decode Files or Information

Upon execution, Metamorfo has unzipped itself after being downloaded to the system and has performed string decryption.[1][3][2]

EnterpriseT1083File and Directory Discovery

Metamorfo has searched the Program Files directories for specific folders and has searched for strings related to its mutexes.[1][4][3]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
2.1
Created
Modified
Raw hash
544ae66f95dc1ef9...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.12.1Current bundle544ae66f95dc…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  2. [2]
    ESET Casbaneiro Oct 2019

    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

    Open source URL
  3. [3]
    FireEye Metamorfo Apr 2018

    Sierra, E., Iglesias, G.. (2018, April 24). Metamorfo Campaigns Targeting Brazilian Users. Retrieved July 30, 2020.

    Open source URL
  4. [4]
    Fortinet Metamorfo Feb 2020

    Zhang, X. (2020, February 4). Another Metamorfo Variant Targeting Customers of Financial Institutions in More Countries. Retrieved July 30, 2020.

    Open source URL
  5. [5]
    Casbaneiro

    (Citation: ESET Casbaneiro Oct 2019)

  6. [6]
    Casbaneiro

    (Citation: ESET Casbaneiro Oct 2019)

  7. [7]
    Casbaneiro

    (Citation: ESET Casbaneiro Oct 2019)

  8. [8]
    ESET Casbaneiro Oct 2019

    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

    Open source URL
  9. [9]
    ESET Casbaneiro Oct 2019

    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

    Open source URL
  10. [10]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  11. [11]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  12. [12]
    Metamorfo

    (Citation: Medium Metamorfo Apr 2020)(Citation: ESET Casbaneiro Oct 2019)

  13. [13]
    Metamorfo

    (Citation: Medium Metamorfo Apr 2020)(Citation: ESET Casbaneiro Oct 2019)

  14. [14]
    Metamorfo

    (Citation: Medium Metamorfo Apr 2020)(Citation: ESET Casbaneiro Oct 2019)

  15. [15]
    mitre-attackS0455
    Open source URL
  16. [16]
    mitre-attackS0455
    Open source URL
  17. [17]
    mitre-attackS0455
    Open source URL
  18. [18]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  19. [19]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  20. [20]
    ESET Casbaneiro Oct 2019

    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

    Open source URL
  21. [21]
    ESET Casbaneiro Oct 2019

    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

    Open source URL
  22. [22]
    FireEye Metamorfo Apr 2018

    Sierra, E., Iglesias, G.. (2018, April 24). Metamorfo Campaigns Targeting Brazilian Users. Retrieved July 30, 2020.

    Open source URL
  23. [23]
    ESET Casbaneiro Oct 2019

    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

    Open source URL
  24. [24]
    ESET Casbaneiro Oct 2019

    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

    Open source URL
  25. [25]
    Fortinet Metamorfo Feb 2020

    Zhang, X. (2020, February 4). Another Metamorfo Variant Targeting Customers of Financial Institutions in More Countries. Retrieved July 30, 2020.

    Open source URL
  26. [26]
    ESET Casbaneiro Oct 2019

    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

    Open source URL
  27. [27]
    ESET Casbaneiro Oct 2019

    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

    Open source URL
  28. [28]
    Fortinet Metamorfo Feb 2020

    Zhang, X. (2020, February 4). Another Metamorfo Variant Targeting Customers of Financial Institutions in More Countries. Retrieved July 30, 2020.

    Open source URL
  29. [29]
    Fortinet Metamorfo Feb 2020

    Zhang, X. (2020, February 4). Another Metamorfo Variant Targeting Customers of Financial Institutions in More Countries. Retrieved July 30, 2020.

    Open source URL
  30. [30]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  31. [31]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  32. [32]
    ESET Casbaneiro Oct 2019

    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

    Open source URL
  33. [33]
    ESET Casbaneiro Oct 2019

    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

    Open source URL
  34. [34]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  35. [35]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  36. [36]
    ESET Casbaneiro Oct 2019

    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

    Open source URL
  37. [37]
    ESET Casbaneiro Oct 2019

    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

    Open source URL
  38. [38]
    Fortinet Metamorfo Feb 2020

    Zhang, X. (2020, February 4). Another Metamorfo Variant Targeting Customers of Financial Institutions in More Countries. Retrieved July 30, 2020.

    Open source URL
  39. [39]
    Fortinet Metamorfo Feb 2020

    Zhang, X. (2020, February 4). Another Metamorfo Variant Targeting Customers of Financial Institutions in More Countries. Retrieved July 30, 2020.

    Open source URL
  40. [40]
    ESET Casbaneiro Oct 2019

    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

    Open source URL
  41. [41]
    ESET Casbaneiro Oct 2019

    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

    Open source URL
  42. [42]
    FireEye Metamorfo Apr 2018

    Sierra, E., Iglesias, G.. (2018, April 24). Metamorfo Campaigns Targeting Brazilian Users. Retrieved July 30, 2020.

    Open source URL
  43. [43]
    FireEye Metamorfo Apr 2018

    Sierra, E., Iglesias, G.. (2018, April 24). Metamorfo Campaigns Targeting Brazilian Users. Retrieved July 30, 2020.

    Open source URL
  44. [44]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  45. [45]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  46. [46]
    ESET Casbaneiro Oct 2019

    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

    Open source URL
  47. [47]
    ESET Casbaneiro Oct 2019

    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

    Open source URL
  48. [48]
    ESET Casbaneiro Oct 2019

    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

    Open source URL
  49. [49]
    ESET Casbaneiro Oct 2019

    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

    Open source URL
  50. [50]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  51. [51]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  52. [52]
    Fortinet Metamorfo Feb 2020

    Zhang, X. (2020, February 4). Another Metamorfo Variant Targeting Customers of Financial Institutions in More Countries. Retrieved July 30, 2020.

    Open source URL
  53. [53]
    Fortinet Metamorfo Feb 2020

    Zhang, X. (2020, February 4). Another Metamorfo Variant Targeting Customers of Financial Institutions in More Countries. Retrieved July 30, 2020.

    Open source URL
  54. [54]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  55. [55]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  56. [56]
    ESET Casbaneiro Oct 2019

    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

    Open source URL
  57. [57]
    ESET Casbaneiro Oct 2019

    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

    Open source URL
  58. [58]
    FireEye Metamorfo Apr 2018

    Sierra, E., Iglesias, G.. (2018, April 24). Metamorfo Campaigns Targeting Brazilian Users. Retrieved July 30, 2020.

    Open source URL
  59. [59]
    FireEye Metamorfo Apr 2018

    Sierra, E., Iglesias, G.. (2018, April 24). Metamorfo Campaigns Targeting Brazilian Users. Retrieved July 30, 2020.

    Open source URL
  60. [60]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  61. [61]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  62. [62]
    ESET Casbaneiro Oct 2019

    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

    Open source URL
  63. [63]
    ESET Casbaneiro Oct 2019

    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

    Open source URL
  64. [64]
    FireEye Metamorfo Apr 2018

    Sierra, E., Iglesias, G.. (2018, April 24). Metamorfo Campaigns Targeting Brazilian Users. Retrieved July 30, 2020.

    Open source URL
  65. [65]
    FireEye Metamorfo Apr 2018

    Sierra, E., Iglesias, G.. (2018, April 24). Metamorfo Campaigns Targeting Brazilian Users. Retrieved July 30, 2020.

    Open source URL
  66. [66]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  67. [67]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  68. [68]
    FireEye Metamorfo Apr 2018

    Sierra, E., Iglesias, G.. (2018, April 24). Metamorfo Campaigns Targeting Brazilian Users. Retrieved July 30, 2020.

    Open source URL
  69. [69]
    FireEye Metamorfo Apr 2018

    Sierra, E., Iglesias, G.. (2018, April 24). Metamorfo Campaigns Targeting Brazilian Users. Retrieved July 30, 2020.

    Open source URL
  70. [70]
    ESET Casbaneiro Oct 2019

    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

    Open source URL
  71. [71]
    ESET Casbaneiro Oct 2019

    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

    Open source URL
  72. [72]
    FireEye Metamorfo Apr 2018

    Sierra, E., Iglesias, G.. (2018, April 24). Metamorfo Campaigns Targeting Brazilian Users. Retrieved July 30, 2020.

    Open source URL
  73. [73]
    FireEye Metamorfo Apr 2018

    Sierra, E., Iglesias, G.. (2018, April 24). Metamorfo Campaigns Targeting Brazilian Users. Retrieved July 30, 2020.

    Open source URL
  74. [74]
    Fortinet Metamorfo Feb 2020

    Zhang, X. (2020, February 4). Another Metamorfo Variant Targeting Customers of Financial Institutions in More Countries. Retrieved July 30, 2020.

    Open source URL
  75. [75]
    Fortinet Metamorfo Feb 2020

    Zhang, X. (2020, February 4). Another Metamorfo Variant Targeting Customers of Financial Institutions in More Countries. Retrieved July 30, 2020.

    Open source URL
  76. [76]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  77. [77]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  78. [78]
    ESET Casbaneiro Oct 2019

    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

    Open source URL
  79. [79]
    ESET Casbaneiro Oct 2019

    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

    Open source URL
  80. [80]
    FireEye Metamorfo Apr 2018

    Sierra, E., Iglesias, G.. (2018, April 24). Metamorfo Campaigns Targeting Brazilian Users. Retrieved July 30, 2020.

    Open source URL
  81. [81]
    FireEye Metamorfo Apr 2018

    Sierra, E., Iglesias, G.. (2018, April 24). Metamorfo Campaigns Targeting Brazilian Users. Retrieved July 30, 2020.

    Open source URL
  82. [82]
    FireEye Metamorfo Apr 2018

    Sierra, E., Iglesias, G.. (2018, April 24). Metamorfo Campaigns Targeting Brazilian Users. Retrieved July 30, 2020.

    Open source URL
  83. [83]
    FireEye Metamorfo Apr 2018

    Sierra, E., Iglesias, G.. (2018, April 24). Metamorfo Campaigns Targeting Brazilian Users. Retrieved July 30, 2020.

    Open source URL
  84. [84]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  85. [85]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  86. [86]
    Fortinet Metamorfo Feb 2020

    Zhang, X. (2020, February 4). Another Metamorfo Variant Targeting Customers of Financial Institutions in More Countries. Retrieved July 30, 2020.

    Open source URL
  87. [87]
    Fortinet Metamorfo Feb 2020

    Zhang, X. (2020, February 4). Another Metamorfo Variant Targeting Customers of Financial Institutions in More Countries. Retrieved July 30, 2020.

    Open source URL
  88. [88]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  89. [89]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  90. [90]
    ESET Casbaneiro Oct 2019

    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

    Open source URL
  91. [91]
    ESET Casbaneiro Oct 2019

    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

    Open source URL
  92. [92]
    FireEye Metamorfo Apr 2018

    Sierra, E., Iglesias, G.. (2018, April 24). Metamorfo Campaigns Targeting Brazilian Users. Retrieved July 30, 2020.

    Open source URL
  93. [93]
    FireEye Metamorfo Apr 2018

    Sierra, E., Iglesias, G.. (2018, April 24). Metamorfo Campaigns Targeting Brazilian Users. Retrieved July 30, 2020.

    Open source URL
  94. [94]
    Fortinet Metamorfo Feb 2020

    Zhang, X. (2020, February 4). Another Metamorfo Variant Targeting Customers of Financial Institutions in More Countries. Retrieved July 30, 2020.

    Open source URL
  95. [95]
    Fortinet Metamorfo Feb 2020

    Zhang, X. (2020, February 4). Another Metamorfo Variant Targeting Customers of Financial Institutions in More Countries. Retrieved July 30, 2020.

    Open source URL
  96. [96]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  97. [97]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  98. [98]
    FireEye Metamorfo Apr 2018

    Sierra, E., Iglesias, G.. (2018, April 24). Metamorfo Campaigns Targeting Brazilian Users. Retrieved July 30, 2020.

    Open source URL
  99. [99]
    FireEye Metamorfo Apr 2018

    Sierra, E., Iglesias, G.. (2018, April 24). Metamorfo Campaigns Targeting Brazilian Users. Retrieved July 30, 2020.

    Open source URL
  100. [100]
    Fortinet Metamorfo Feb 2020

    Zhang, X. (2020, February 4). Another Metamorfo Variant Targeting Customers of Financial Institutions in More Countries. Retrieved July 30, 2020.

    Open source URL
  101. [101]
    Fortinet Metamorfo Feb 2020

    Zhang, X. (2020, February 4). Another Metamorfo Variant Targeting Customers of Financial Institutions in More Countries. Retrieved July 30, 2020.

    Open source URL
  102. [102]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  103. [103]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  104. [104]
    FireEye Metamorfo Apr 2018

    Sierra, E., Iglesias, G.. (2018, April 24). Metamorfo Campaigns Targeting Brazilian Users. Retrieved July 30, 2020.

    Open source URL
  105. [105]
    FireEye Metamorfo Apr 2018

    Sierra, E., Iglesias, G.. (2018, April 24). Metamorfo Campaigns Targeting Brazilian Users. Retrieved July 30, 2020.

    Open source URL
  106. [106]
    FireEye Metamorfo Apr 2018

    Sierra, E., Iglesias, G.. (2018, April 24). Metamorfo Campaigns Targeting Brazilian Users. Retrieved July 30, 2020.

    Open source URL
  107. [107]
    FireEye Metamorfo Apr 2018

    Sierra, E., Iglesias, G.. (2018, April 24). Metamorfo Campaigns Targeting Brazilian Users. Retrieved July 30, 2020.

    Open source URL
  108. [108]
    FireEye Metamorfo Apr 2018

    Sierra, E., Iglesias, G.. (2018, April 24). Metamorfo Campaigns Targeting Brazilian Users. Retrieved July 30, 2020.

    Open source URL
  109. [109]
    FireEye Metamorfo Apr 2018

    Sierra, E., Iglesias, G.. (2018, April 24). Metamorfo Campaigns Targeting Brazilian Users. Retrieved July 30, 2020.

    Open source URL
  110. [110]
    ESET Casbaneiro Oct 2019

    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

    Open source URL
  111. [111]
    ESET Casbaneiro Oct 2019

    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

    Open source URL
  112. [112]
    Fortinet Metamorfo Feb 2020

    Zhang, X. (2020, February 4). Another Metamorfo Variant Targeting Customers of Financial Institutions in More Countries. Retrieved July 30, 2020.

    Open source URL
  113. [113]
    Fortinet Metamorfo Feb 2020

    Zhang, X. (2020, February 4). Another Metamorfo Variant Targeting Customers of Financial Institutions in More Countries. Retrieved July 30, 2020.

    Open source URL
  114. [114]
    Fortinet Metamorfo Feb 2020

    Zhang, X. (2020, February 4). Another Metamorfo Variant Targeting Customers of Financial Institutions in More Countries. Retrieved July 30, 2020.

    Open source URL
  115. [115]
    Fortinet Metamorfo Feb 2020

    Zhang, X. (2020, February 4). Another Metamorfo Variant Targeting Customers of Financial Institutions in More Countries. Retrieved July 30, 2020.

    Open source URL
  116. [116]
    ESET Casbaneiro Oct 2019

    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

    Open source URL
  117. [117]
    ESET Casbaneiro Oct 2019

    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

    Open source URL
  118. [118]
    FireEye Metamorfo Apr 2018

    Sierra, E., Iglesias, G.. (2018, April 24). Metamorfo Campaigns Targeting Brazilian Users. Retrieved July 30, 2020.

    Open source URL
  119. [119]
    FireEye Metamorfo Apr 2018

    Sierra, E., Iglesias, G.. (2018, April 24). Metamorfo Campaigns Targeting Brazilian Users. Retrieved July 30, 2020.

    Open source URL
  120. [120]
    Fortinet Metamorfo Feb 2020

    Zhang, X. (2020, February 4). Another Metamorfo Variant Targeting Customers of Financial Institutions in More Countries. Retrieved July 30, 2020.

    Open source URL
  121. [121]
    Fortinet Metamorfo Feb 2020

    Zhang, X. (2020, February 4). Another Metamorfo Variant Targeting Customers of Financial Institutions in More Countries. Retrieved July 30, 2020.

    Open source URL
  122. [122]
    ESET Casbaneiro Oct 2019

    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

    Open source URL
  123. [123]
    ESET Casbaneiro Oct 2019

    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

    Open source URL
  124. [124]
    Fortinet Metamorfo Feb 2020

    Zhang, X. (2020, February 4). Another Metamorfo Variant Targeting Customers of Financial Institutions in More Countries. Retrieved July 30, 2020.

    Open source URL
  125. [125]
    Fortinet Metamorfo Feb 2020

    Zhang, X. (2020, February 4). Another Metamorfo Variant Targeting Customers of Financial Institutions in More Countries. Retrieved July 30, 2020.

    Open source URL
  126. [126]
    ESET Casbaneiro Oct 2019

    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

    Open source URL
  127. [127]
    ESET Casbaneiro Oct 2019

    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

    Open source URL
  128. [128]
    FireEye Metamorfo Apr 2018

    Sierra, E., Iglesias, G.. (2018, April 24). Metamorfo Campaigns Targeting Brazilian Users. Retrieved July 30, 2020.

    Open source URL
  129. [129]
    FireEye Metamorfo Apr 2018

    Sierra, E., Iglesias, G.. (2018, April 24). Metamorfo Campaigns Targeting Brazilian Users. Retrieved July 30, 2020.

    Open source URL
  130. [130]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  131. [131]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  132. [132]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  133. [133]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  134. [134]
    Fortinet Metamorfo Feb 2020

    Zhang, X. (2020, February 4). Another Metamorfo Variant Targeting Customers of Financial Institutions in More Countries. Retrieved July 30, 2020.

    Open source URL
  135. [135]
    Fortinet Metamorfo Feb 2020

    Zhang, X. (2020, February 4). Another Metamorfo Variant Targeting Customers of Financial Institutions in More Countries. Retrieved July 30, 2020.

    Open source URL
  136. [136]
    FireEye Metamorfo Apr 2018

    Sierra, E., Iglesias, G.. (2018, April 24). Metamorfo Campaigns Targeting Brazilian Users. Retrieved July 30, 2020.

    Open source URL
  137. [137]
    FireEye Metamorfo Apr 2018

    Sierra, E., Iglesias, G.. (2018, April 24). Metamorfo Campaigns Targeting Brazilian Users. Retrieved July 30, 2020.

    Open source URL
  138. [138]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  139. [139]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  140. [140]
    FireEye Metamorfo Apr 2018

    Sierra, E., Iglesias, G.. (2018, April 24). Metamorfo Campaigns Targeting Brazilian Users. Retrieved July 30, 2020.

    Open source URL
  141. [141]
    FireEye Metamorfo Apr 2018

    Sierra, E., Iglesias, G.. (2018, April 24). Metamorfo Campaigns Targeting Brazilian Users. Retrieved July 30, 2020.

    Open source URL
  142. [142]
    Fortinet Metamorfo Feb 2020

    Zhang, X. (2020, February 4). Another Metamorfo Variant Targeting Customers of Financial Institutions in More Countries. Retrieved July 30, 2020.

    Open source URL
  143. [143]
    Fortinet Metamorfo Feb 2020

    Zhang, X. (2020, February 4). Another Metamorfo Variant Targeting Customers of Financial Institutions in More Countries. Retrieved July 30, 2020.

    Open source URL
  144. [144]
    ESET Casbaneiro Oct 2019

    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

    Open source URL
  145. [145]
    ESET Casbaneiro Oct 2019

    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

    Open source URL
  146. [146]
    ESET Casbaneiro Oct 2019

    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

    Open source URL
  147. [147]
    ESET Casbaneiro Oct 2019

    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

    Open source URL
  148. [148]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  149. [149]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  150. [150]
    ESET Casbaneiro Oct 2019

    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

    Open source URL
  151. [151]
    FireEye Metamorfo Apr 2018

    Sierra, E., Iglesias, G.. (2018, April 24). Metamorfo Campaigns Targeting Brazilian Users. Retrieved July 30, 2020.

    Open source URL
  152. [152]
    Fortinet Metamorfo Feb 2020

    Zhang, X. (2020, February 4). Another Metamorfo Variant Targeting Customers of Financial Institutions in More Countries. Retrieved July 30, 2020.

    Open source URL
  153. [153]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  154. [154]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  155. [155]
    ESET Casbaneiro Oct 2019

    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

    Open source URL
  156. [156]
    FireEye Metamorfo Apr 2018

    Sierra, E., Iglesias, G.. (2018, April 24). Metamorfo Campaigns Targeting Brazilian Users. Retrieved July 30, 2020.

    Open source URL
  157. [157]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  158. [158]
    ESET Casbaneiro Oct 2019

    ESET Research. (2019, October 3). Casbaneiro: peculiarities of this banking Trojan that affects Brazil and Mexico. Retrieved September 23, 2021.

    Open source URL
  159. [159]
    FireEye Metamorfo Apr 2018

    Sierra, E., Iglesias, G.. (2018, April 24). Metamorfo Campaigns Targeting Brazilian Users. Retrieved July 30, 2020.

    Open source URL
  160. [160]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
  161. [161]
    FireEye Metamorfo Apr 2018

    Sierra, E., Iglesias, G.. (2018, April 24). Metamorfo Campaigns Targeting Brazilian Users. Retrieved July 30, 2020.

    Open source URL
  162. [162]
    Fortinet Metamorfo Feb 2020

    Zhang, X. (2020, February 4). Another Metamorfo Variant Targeting Customers of Financial Institutions in More Countries. Retrieved July 30, 2020.

    Open source URL
  163. [163]
    Medium Metamorfo Apr 2020

    Erlich, C. (2020, April 3). The Avast Abuser: Metamorfo Banking Malware Hides By Abusing Avast Executable. Retrieved May 26, 2020.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.