The Grandoreiro banking Trojan continues to pose a significant threat to banking customers, primarily in Latin America, more than two years after law enforcement disrupted its operations.

The latest evidence is a new campaign using the 12-year-old payload that’s targeting users in Mexico. The operators are using DLL sideloading and a legitimate file-management application to deliver the malware.

Telemetry from the campaign that security vendor Acronis analyzed showed a handful of victims in North America and Europe as well. But “the overall distribution continues to reflect the malware’s long-standing focus on Spanish-speaking regions,” Acronis said in a report this week.

More importantly, “this campaign highlights the continued evolution of Grandoreiro and its operators’ focus on stealth and evasion,” Acronis said.

Persistent Brazilian Cyber Threat Targets LatAm Banking

Grandoreiro is a banking Trojan that first surfaced in 2016. Written in Delphi by likely Brazilian Portuguese-speaking malware developers, it initially targeted banking customers in Brazil but has since expanded to other Latin American countries and regions around the world.

Related:China-Linked Hacker Shows AI Capabilities in APAC Attack

In 2024, researchers at IBM — among several security firms tracking the malware — found Grandoreiro targeting customers of more than 1,500 banks in more than 60 countries across South and Central America, Europe, Africa and the Indo-Pacific region. IBM concluded that it was likely being operated as a malware-as-a-service (MaaS) operation, which could make it more difficult to eradicate completely.

Later that year, Kaspersky put the number of targeted banks at 1,700 across 45 countries, and estimated that Grandoreiro and its variants accounted for about 5% of all banking-Trojan attacks in 2024. The malware is primarily used to steal banking credentials and other financial information, with capabilities including keystroke logging, screen sharing, and remote control of infected devices.

Grandoreiro is one of numerous banking Trojans that attackers have used over the years to steal credentials and other information for accessing online banking and financial accounts and to steal money from them. Other notable examples include Dridex, SharkBot, mobile banking Trojan Xenomorph, and Ursnif, one of several banking Trojans that attackers repurposed for other malicious activities. Law enforcement in Brazil and Spain, with the help of Interpol, disrupted Grandoreiro operations in 2024 and arrested five administrators behind it. Since then, its operations have scaled down considerably … but clearly have not entirely stopped.

Related:Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition

Cyberattack Campaign Gets Stealthy in Mexico

In the latest campaign, Grandoreiro’s operators are using a zip archive disguised as an invoice to deliver the malware, most likely via spam email, according to Acronis. The archive contains what appear to be legitimate PDF and XML documents that serve as decoys, making the file appear benign to antivirus and other security tools. It also includes a copy of Duplicate Files Finder, a legitimate application for finding and removing redundant files, that the attackers have repurposed to load Grandoreiro.

The attack relies on DLL sideloading, a technique in which malware abuses a legitimate application to load a malicious dynamic link library. In this case, the attackers modified Duplicate Files Finder so that when it runs, it also loads malicious code that launches Grandoreiro. Acronis found that the malicious component first checks the victim’s computer for security controls and signs that it might be running in a security sandbox. If the system passes those checks, the malware communicates with the attackers’ command-and-control (C2) server and downloads the main Grandoreiro payload.

What makes the latest version of the loader notable, according to Acronis, is its extensive anti-analysis and anti-forensics features, all designed to prevent researchers and automated security systems from examining it. Before contacting its C2 infrastructure for instance, the loader checks system uptime and for the presence of a particular combination of applications, like Google Chrome, Firefox, CCleaner, and Firefox Edge, to make sure it is not running in a sandbox. It also checks available memory and processors, disk space, screen resolution, recent user activity, and for the presence of nearly 50 security, debugging, reverse-engineering, and network-monitoring tools.

Related:Angola’s Largest Telco Breached Hours Before IPO

Meanwhile, the decision by the operators to use a “heavily protected loader” to deliver Grandoreiro also suggests a new, deliberate focus on separating initial access from the malware’s long-term capabilities. “While overall activity associated with Grandoreiro has decreased compared to its peak, the campaign shows that it remains active and continues to adapt its tooling and infrastructure.”





Source link

#

Comments are closed