Grandoreiro, a banking Trojan that has been active for years, has resurfaced with a new campaign targeting banking users in Mexico. The latest activity shows that the malware is still a serious threat even after law enforcement disrupted parts of its operation. Security researchers found that the campaign is using updated techniques designed to make detection and analysis more difficult. The activity mainly continues the malware’s long-standing focus on Spanish-speaking regions.
The latest campaign was analyzed by cybersecurity company Acronis and involves the use of the Grandoreiro payload that has been around for many years. Researchers observed victims mainly in Mexico, while a smaller number of victims were also seen in North America and Europe. According to Acronis, the overall distribution still reflects Grandoreiro’s strong focus on Latin America. The campaign also shows that the operators continue to improve their tools and infrastructure.
Grandoreiro first appeared in 2016 and was developed as a banking Trojan written in Delphi. It initially focused on customers in Brazil before expanding to other countries and regions. In 2024, researchers found versions targeting more than 1,500 banks across more than 60 countries. Kaspersky later reported that newer versions targeted about 1,700 banks in 45 countries and territories, showing how widely the malware had spread.
The malware is mainly designed to steal banking credentials and financial information from infected computers. It can use techniques such as recording keystrokes, sharing the victim’s screen and remotely controlling an infected device. Grandoreiro has also been linked to a malware-as-a-service model, which can make the threat harder to eliminate because different operators may use or develop different versions of the malware.
In the latest Mexico campaign, attackers reportedly use a ZIP archive disguised as an invoice, most likely delivered through spam emails. Inside the archive are seemingly legitimate PDF and XML files that act as decoys. The package also contains a legitimate file-management program called Duplicate Files Finder, which has been modified by the attackers to help load the malicious Grandoreiro code. This makes the attack look less suspicious to the victim.
The attack uses a technique known as DLL sideloading, where a legitimate application is abused to load a malicious DLL file. Before continuing, the malicious component checks the computer for security controls and signs that it may be running inside a security sandbox. It also checks system uptime, memory, processors, disk space, screen resolution and recent user activity. These checks are intended to make analysis and detection more difficult.
Researchers also found that the loader searches for nearly 50 security, debugging, reverse-engineering and network-monitoring tools. If the system passes its checks, the malware contacts its command-and-control server and downloads the main Grandoreiro payload. This heavily protected loader shows that the attackers are placing greater attention on hiding the malware before it reaches the final stage. Acronis said the campaign demonstrates continued evolution in Grandoreiro’s tooling and infrastructure.
Although Grandoreiro activity has decreased from its previous peak, the latest campaign confirms that the threat has not disappeared. Law enforcement agencies in Brazil and Spain, with support from Interpol, disrupted the operation in 2024 and arrested five administrators, but the malware continued in a reduced form. The renewed activity in Mexico shows that Grandoreiro operators are still adapting their methods, making careful handling of unexpected email attachments and invoice files especially important for banking users.
Stay alert, and keep your security measures updated!
Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news