Grandoreiro Malware Targets Portuguese Banks and Latin American Companies
Key Takeaways Grandoreiro, a banking trojan active since 2016, has launched new, sophisticated campaigns. The primary targets are financial institutions and businesses in Portugal, Spain, Mexico, and...
Key Takeaways
- Grandoreiro, a banking trojan active since 2016, has launched new, sophisticated campaigns.
- The primary targets are financial institutions and businesses in Portugal, Spain, Mexico, and other Latin American countries.
- The malware utilizes advanced evasion techniques, including DLL side-loading, obfuscated VBS scripts, and command-and-control (C2) infrastructure hosted on major cloud platforms like Google Cloud, Microsoft Azure, and Amazon.
- Initial infection vectors rely on phishing, leading to financial fraud through credential theft, keylogging, and fake banking overlays.
Grandoreiro Banking Trojan Resurfaces with Advanced Campaigns Targeting European and Latin American Financial Sectors
The persistent banking trojan, Grandoreiro, has re-emerged with renewed vigor, launching sophisticated attack campaigns specifically targeting banking customers and businesses across Portugal and various Latin American nations, including Spain and Mexico. This resurgence highlights the enduring threat posed by a malware family that has proven resilient despite previous law enforcement interventions.
Table Of Content
First identified in 2016, Grandoreiro has consistently adapted its tactics. Although joint operations by INTERPOL and local authorities in 2021 and 2024 led to arrests in Spain, Brazil, and Argentina, these actions only dismantled a portion of the criminal network. The remaining elements have continued their operations, demonstrating the group’s organizational fortitude and ongoing threat capability.
Sophisticated Delivery and Evasion Techniques
New research from WatchGuard details two distinct, active Grandoreiro campaigns. Both leverage phishing as the initial point of compromise, luring victims into clicking malicious links. These links subsequently deploy the malware onto target systems using advanced techniques designed to bypass traditional security measures.
One campaign employs a DLL side-loading technique, disguising four malicious DLL files—libwebp.dll, mingw10.dll, libffi-6.dll, and libpng15.dll—as legitimate software components. These files, developed with Delphi 11, incorporate SGC WebSockets components linked to WebRTC, a widely trusted real-time communication protocol. This enables the malicious traffic to mimic standard video call data, making it significantly harder to detect within network flows.
A key aspect of these campaigns is the strategic use of legitimate cloud platforms for command-and-control infrastructure. The malicious DLLs establish connections to Google Cloud Pub/Sub, Microsoft Azure (via MQTT protocol), and Amazon (also via MQTT). By routing C2 traffic through these ubiquitous cloud services, attackers can blend their malicious communications with legitimate network activity, particularly web conferencing traffic, which is often less scrutinized.
The malware delivery mechanism in this campaign involves phishing links redirecting victims to Dropbox, where a ZIP archive containing the malicious DLL is hosted. This abuse of trusted cloud storage platforms further complicates detection efforts.
Grandoreiro also incorporates robust anti-analysis features. Before full execution, the malware actively scans for debugging tools, virtual environments, and installed security software. It checks for specific computer names and directory paths commonly used by security researchers. Furthermore, it can force web browsers into Kiosk Mode, locking the screen to a single full-screen window to obscure its activities. Interestingly, Chinese language strings were also discovered embedded within the malware’s code.
Geofenced VBS Script Deployment
The second observed Grandoreiro campaign employs a different, yet equally deceptive, strategy. Victims are directed to a fake web page hosted on Contabo servers. This page is geofenced, ensuring it is only displayed to users within the targeted geographical regions.
From this fake page, users are prompted to download a file from Mediafire. This downloaded file contains a heavily obfuscated VBS script, which, when executed, proceeds to install the Grandoreiro malware on the victim’s machine.
Upon execution, this variant of Grandoreiro displays a deceptive Adobe Reader update message, serving as a distraction while the malware performs background checks. It queries the victim’s geographical location using a public IP lookup service and verifies that the system is not a research environment. Once these checks are complete, the malware proceeds to steal credentials, log keystrokes, monitor clipboard contents, and display convincing fake banking overlays designed to capture sensitive login details.
The comprehensive nature of these attacks, combined with hardcoded references to over 20 Portuguese banks, including Caixa Geral de Depositos, Millennium, Novobanco, and Santander, as well as financial services like Revolut and Wise, underscores the significant financial risk posed to individuals and businesses across the affected regions.
What You Should Do
- Enhance Email Security: Implement advanced email filtering solutions capable of detecting sophisticated phishing attempts, including those with malicious links to cloud storage services.
- Promote Security Awareness: Conduct regular training for employees on recognizing phishing emails, suspicious links, and unexpected downloads, emphasizing the dangers of clicking on unsolicited attachments or URLs.
- Implement Layered Security: Move beyond basic endpoint protection. Deploy advanced endpoint detection and response (EDR) solutions, network detection and response (NDR), and security information and event management (SIEM) systems for comprehensive visibility and behavioral detection.
- Monitor Cloud Traffic: Actively monitor network traffic, especially to and from legitimate cloud services like Google Cloud, Microsoft Azure, and Amazon, for anomalous patterns that might indicate hidden malicious communications.
- Regularly Update Software: Ensure all operating systems, applications, and security software are kept up-to-date with the latest patches to mitigate known vulnerabilities.
- Employ Multi-Factor Authentication (MFA): Mandate MFA for all sensitive accounts, especially banking and corporate logins, to significantly reduce the impact of stolen credentials.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.