‘Grandoreiro’ Malware Resurfaces With Mexico Campaign

A Resurgent Banking Trojan Threatens Mexico’s Financial Sector

The Grandoreiro banking Trojan has emerged from its apparent hiatus, targeting users in Mexico with a new campaign that showcases its authors’ determination to evade detection and stay one step ahead of security measures. This resurgence is a stark reminder that cyber threats never truly disappear – they adapt and evolve to find new vulnerabilities.

For over two years, law enforcement had disrupted Grandoreiro’s operations, arresting five administrators behind it in 2024. However, the malware’s operators have now reactivated their efforts, focusing on Mexico with a campaign that leverages stealthy tactics to deliver the malicious payload. Acronis, a cybersecurity firm, analyzed telemetry from this campaign and found evidence of victims in North America and Europe as well.

Grandoreiro’s evolution is characterized by its increasing reliance on sophisticated techniques to evade detection. The malware employs DLL sideloading, where it uses a legitimate application to load malicious code, making it harder for security tools to identify the threat. In this case, the attackers modified Duplicate Files Finder, a legitimate file-management tool, to load Grandoreiro when run.

The attackers’ use of a zip archive disguised as an invoice serves as a decoy, concealing the malware within what appears to be benign documents. This approach is designed to bypass antivirus and security tools, which may flag the attachment as harmless. Once inside the victim’s system, the malicious component checks for security controls and signs that might indicate a sandbox environment before communicating with the attackers’ command-and-control server.

The Grandoreiro banking Trojan has been around since 2016, initially targeting Brazilian banking customers but expanding to other Latin American countries and regions worldwide. Its operators are believed to be likely Brazilian Portuguese-speaking malware developers who have used it as a malware-as-a-service operation – making it harder to eradicate completely.

Grandoreiro’s resurgence serves as a warning that even the most seemingly defeated threats can return with renewed vigor. This campaign highlights the ongoing cat-and-mouse game between attackers and defenders, where both sides continually adapt and evolve their tactics.

To mitigate this threat, users should remain vigilant when receiving unsolicited attachments or emails, especially those containing zip archives or PDF documents. Legitimate file-management tools like Duplicate Files Finder should be used with caution, and regular security software updates are essential to stay ahead of emerging threats.


Source: Dark Reading — 2026-08-20