Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
UNC6671 Automates Microsoft 365 Data Theft via Session Hijacking
August 7, 2026
Papyrus Ad Fraud Abuses Hidden WebViews to Fake User Engagement
August 7, 2026
Critical Flaws in Enterprise Java Platforms Let Attackers Execute Remote Code
August 7, 2026
Home/Threats/Grandoreiro Malware Targets Portuguese Banks and Latin American Companies
Threats

Grandoreiro Malware Targets Portuguese Banks and Latin American Companies

Key Takeaways Grandoreiro, a banking trojan active since 2016, has launched new, sophisticated campaigns. The primary targets are financial institutions and businesses in Portugal, Spain, Mexico, and...

David kimber
David kimber
May 27, 2026 4 Min Read
61 0

Key Takeaways

  • Grandoreiro, a banking trojan active since 2016, has launched new, sophisticated campaigns.
  • The primary targets are financial institutions and businesses in Portugal, Spain, Mexico, and other Latin American countries.
  • The malware utilizes advanced evasion techniques, including DLL side-loading, obfuscated VBS scripts, and command-and-control (C2) infrastructure hosted on major cloud platforms like Google Cloud, Microsoft Azure, and Amazon.
  • Initial infection vectors rely on phishing, leading to financial fraud through credential theft, keylogging, and fake banking overlays.

Grandoreiro Banking Trojan Resurfaces with Advanced Campaigns Targeting European and Latin American Financial Sectors

The persistent banking trojan, Grandoreiro, has re-emerged with renewed vigor, launching sophisticated attack campaigns specifically targeting banking customers and businesses across Portugal and various Latin American nations, including Spain and Mexico. This resurgence highlights the enduring threat posed by a malware family that has proven resilient despite previous law enforcement interventions.

Table Of Content

  • Key Takeaways
  • Grandoreiro Banking Trojan Resurfaces with Advanced Campaigns Targeting European and Latin American Financial Sectors
  • Sophisticated Delivery and Evasion Techniques
  • Geofenced VBS Script Deployment
  • What You Should Do

First identified in 2016, Grandoreiro has consistently adapted its tactics. Although joint operations by INTERPOL and local authorities in 2021 and 2024 led to arrests in Spain, Brazil, and Argentina, these actions only dismantled a portion of the criminal network. The remaining elements have continued their operations, demonstrating the group’s organizational fortitude and ongoing threat capability.

Sophisticated Delivery and Evasion Techniques

New research from WatchGuard details two distinct, active Grandoreiro campaigns. Both leverage phishing as the initial point of compromise, luring victims into clicking malicious links. These links subsequently deploy the malware onto target systems using advanced techniques designed to bypass traditional security measures.

One campaign employs a DLL side-loading technique, disguising four malicious DLL files—libwebp.dll, mingw10.dll, libffi-6.dll, and libpng15.dll—as legitimate software components. These files, developed with Delphi 11, incorporate SGC WebSockets components linked to WebRTC, a widely trusted real-time communication protocol. This enables the malicious traffic to mimic standard video call data, making it significantly harder to detect within network flows.

A key aspect of these campaigns is the strategic use of legitimate cloud platforms for command-and-control infrastructure. The malicious DLLs establish connections to Google Cloud Pub/Sub, Microsoft Azure (via MQTT protocol), and Amazon (also via MQTT). By routing C2 traffic through these ubiquitous cloud services, attackers can blend their malicious communications with legitimate network activity, particularly web conferencing traffic, which is often less scrutinized.

The malware delivery mechanism in this campaign involves phishing links redirecting victims to Dropbox, where a ZIP archive containing the malicious DLL is hosted. This abuse of trusted cloud storage platforms further complicates detection efforts.

Grandoreiro also incorporates robust anti-analysis features. Before full execution, the malware actively scans for debugging tools, virtual environments, and installed security software. It checks for specific computer names and directory paths commonly used by security researchers. Furthermore, it can force web browsers into Kiosk Mode, locking the screen to a single full-screen window to obscure its activities. Interestingly, Chinese language strings were also discovered embedded within the malware’s code.

Geofenced VBS Script Deployment

The second observed Grandoreiro campaign employs a different, yet equally deceptive, strategy. Victims are directed to a fake web page hosted on Contabo servers. This page is geofenced, ensuring it is only displayed to users within the targeted geographical regions.

From this fake page, users are prompted to download a file from Mediafire. This downloaded file contains a heavily obfuscated VBS script, which, when executed, proceeds to install the Grandoreiro malware on the victim’s machine.

Upon execution, this variant of Grandoreiro displays a deceptive Adobe Reader update message, serving as a distraction while the malware performs background checks. It queries the victim’s geographical location using a public IP lookup service and verifies that the system is not a research environment. Once these checks are complete, the malware proceeds to steal credentials, log keystrokes, monitor clipboard contents, and display convincing fake banking overlays designed to capture sensitive login details.

The comprehensive nature of these attacks, combined with hardcoded references to over 20 Portuguese banks, including Caixa Geral de Depositos, Millennium, Novobanco, and Santander, as well as financial services like Revolut and Wise, underscores the significant financial risk posed to individuals and businesses across the affected regions.

What You Should Do

  • Enhance Email Security: Implement advanced email filtering solutions capable of detecting sophisticated phishing attempts, including those with malicious links to cloud storage services.
  • Promote Security Awareness: Conduct regular training for employees on recognizing phishing emails, suspicious links, and unexpected downloads, emphasizing the dangers of clicking on unsolicited attachments or URLs.
  • Implement Layered Security: Move beyond basic endpoint protection. Deploy advanced endpoint detection and response (EDR) solutions, network detection and response (NDR), and security information and event management (SIEM) systems for comprehensive visibility and behavioral detection.
  • Monitor Cloud Traffic: Actively monitor network traffic, especially to and from legitimate cloud services like Google Cloud, Microsoft Azure, and Amazon, for anomalous patterns that might indicate hidden malicious communications.
  • Regularly Update Software: Ensure all operating systems, applications, and security software are kept up-to-date with the latest patches to mitigate known vulnerabilities.
  • Employ Multi-Factor Authentication (MFA): Mandate MFA for all sensitive accounts, especially banking and corporate logins, to significantly reduce the impact of stolen credentials.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackHackerMalwarephishingSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

npm Registry Flaw Lets Attackers Distribute Malware, Steal Wallets

Next Post

Tycoon 2FA AiTM Kit Bypasses MFA for Entra ID, Google Workspace

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Zbtlink Router Backdoor Affects 20+ Models
August 7, 2026
OpenAI Expands GPT-3.5 Access With Unlimited Chats for All Users
August 7, 2026
SilverFox Hijacks Drivers to Disable Security Tools
August 7, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us