Grandoreiro banking trojan resurfaces in a DLL sideloading campaign that abuses Duplicate Files Finder to hit Mexico and Latin America.
#Grandoreiro #BankingTrojan #DLLSideloading #Malware #Cybersecurity #LatinAmerica
Live and recent posts from across the Fediverse tagged #grandoreiro, aggregated by home.social.
Grandoreiro banking trojan resurfaces in a DLL sideloading campaign that abuses Duplicate Files Finder to hit Mexico and Latin America.
#Grandoreiro #BankingTrojan #DLLSideloading #Malware #Cybersecurity #LatinAmerica
Grandoreiro Banking Trojan Resurfaces in Mexico With DLL Sideloading Campaign - https://www.redpacketsecurity.com/grandoreiro-resurfaces-in-mexico-with-new-dll-sideloading-campaign/
Over the past days, active #malspam campaigns targeting LatAm users 🇦🇷🇧🇷🇲🇽 have been delivering the Grandoreiro banking trojan 🏦💰
📧 Email ➔ 📜 JS file ➔ 📑 Fake PDF download
Final payload is hosted on MediaFire 🔥 free file hosting
C2 network traffic is rather trivial to detect as #Grandoreiro is using Embarcadero Delphi compilation tools' HTTP user agent 🖥️⤵️
User-Agent: Embarcadero URI Client/1.0
🔎 Botnet C2 domain resolved via Google DNS-over-HTTPS (DoH): devilmaycry.servehumour .com 👀
📡 Grandoreiro botnet C2s hosted at AWS:
54.80.154.193
54.91.129.132
54.91.223.28
🌐 Payloads URLs:
https://urlhaus.abuse.ch/browse/tag/Grandoreiro/
📄 Malware samples:
https://bazaar.abuse.ch/browse/signature/Grandoreiro/
🦊 Relevant IOCs are available on ThreatFox:
https://threatfox.abuse.ch/browse/malware/win.grandoreiro/
📰 Grandoreiro Banking Trojan Resurges, Targeting Banks in Spain and Latin America
Grandoreiro banking trojan is back. 📈 New campaigns are targeting banks and customers in Spain and Latin America, using phishing and DLL side-loading to steal credentials with fake overlays. 🏦 #Grandoreiro #Malware #BankingTrojan #Phishing #Fintech
🌐 cyber[.]netsecops[.]io
#WatchGuard telemetry identified #Grandoreiro-linked activity targeting #Europe and Latin America, including campaigns that abuse DLL side-loading, WebRTC-related components, legitimate cloud and file-sharing services, and malicious VBS delivery.
🔗 wgrd.tech/4uBCTOq
Malware Campaigns Target Windows, Android Users in Global Finance Sector
Global finance sector faces a double threat as malware campaigns target Windows and Android users, with attackers using clever tactics like hiding in trusted traffic and selling mobile RATs as turnkey services. Two recent campaigns, one using Grandoreiro malware in Portugal, Spain, and Mexico, and another using a new BTMOB trojan in…
#Grandoreiro #BankingMalware #Windows #Android #FinanceSector
Malware Campaigns Target Windows, Android Users in Global Finance Sector
Global finance sector faces a double threat as malware campaigns target Windows and Android users, with attackers using clever tactics like hiding in trusted traffic and selling mobile RATs as turnkey services. Two recent campaigns, one using Grandoreiro malware in Portugal, Spain, and Mexico, and another using a new BTMOB trojan in…
#Grandoreiro #BankingMalware #Windows #Android #FinanceSector
How Banking Trojan Grandoreiro is Evolving Tactics To Attack Victims in LATAM https://cybersecuritynews.com/how-banking-trojan-grandoreiro-is-evolving-tactics-to-attack-victims-in-latam/ #CyberSecurityNews #cybersecurity #Grandoreiro #Phishing #phishing #ANY.RUN #Malware
Grandoreiro Strikes Again: Geofenced Phishing Attacks Target LATAM https://hackread.com/grandoreiro-strikes-geofenced-phishing-attacks-latam/ #Cybersecurity #PhishingScam #CyberAttack #Grandoreiro #Security #Phishing #Android #Malware #TROJAN #LATAM #Scam
Grandoreiro Strikes Again: Geofenced Phishing Attacks Target LATAM – Source:hackread.com https://ciso2ciso.com/grandoreiro-strikes-again-geofenced-phishing-attacks-target-latam-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #cybersecurity #PhishingScam #CyberAttack #Grandoreiro #Hackread #Phishing #security #android #malware #trojan #LATAM #Scam
Fresh Grandoreiro Banking Trojan Campaigns Target Latin America, Europe – Source: www.securityweek.com https://ciso2ciso.com/fresh-grandoreiro-banking-trojan-campaigns-target-latin-america-europe-source-www-securityweek-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #Malware&Threats #securityweekcom #bankingtrojan #securityweek #Grandoreiro #Malware #Trojan
Fresh Grandoreiro Banking Trojan Campaigns Target Latin America, Europe https://www.securityweek.com/fresh-grandoreiro-banking-trojan-campaigns-target-latin-america-europe/ #Malware&Threats #bankingtrojan #Grandoreiro #malware #trojan
Advierten sobre Grandoreiro, troyano brasileño que permite hacer operaciones bancarias fraudulentas desde la PC de la víctima https://blog.elhacker.net/2025/03/advierten-sobre-grandoreiro-troyano.html #grandoreiro #bancario #Malware #troyano
Сrimeware and financial cyberthreats in 2025 – Source: securelist.com https://ciso2ciso.com/%D1%81rimeware-and-financial-cyberthreats-in-2025-source-securelist-com/ #Vulnerabilitiesandexploits #KasperskySecurityBulletin #rssfeedpostgeneratorecho #zerodayvulnerabilities #CyberSecurityNews #Financialmalware #Financialthreats #machinelearning #Mobilethreats #securelistcom #Trojanstealer #TrojanBanker #Grandoreiro #Hacktivists #predictions #opensource #ransomware #crimeware #backdoor #AI
New Grandoreiro Banking Malware Variants Emerge with Advanced Tactics to Evade Detection – Source:thehackernews.com https://ciso2ciso.com/new-grandoreiro-banking-malware-variants-emerge-with-advanced-tactics-to-evade-detection-sourcethehackernews-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #TheHackerNews #Grandoreiro
Grandoreiro, the global trojan with grandiose goals – Source: securelist.com https://ciso2ciso.com/grandoreiro-the-global-trojan-with-grandiose-goals-source-securelist-com/ #rssfeedpostgeneratorecho #MalwareDescriptions #MalwareTechnologies #CyberSecurityNews #Financialmalware #Financialthreats #securelistcom #TrojanBanker #Grandoreiro #Cybercrime #crimeware #Malware #Trojan
Grandoreiro, the global trojan with grandiose ambitions – Source: securelist.com https://ciso2ciso.com/grandoreiro-the-global-trojan-with-grandiose-ambitions-source-securelist-com/ #rssfeedpostgeneratorecho #MalwareDescriptions #MalwareTechnologies #CyberSecurityNews #Financialmalware #Financialthreats #securelistcom #TrojanBanker #Grandoreiro #Cybercrime #crimeware #Malware #Trojan
Resumen de las últimas 24 horas en seguridad informática: "CIBERSEGURIDAD EN VUELO: DragonJAR Security Conference 2024 en Bogotá explora ciberseguridad aeroespacial. AT&T paga $370,000 para borrar registros robados. Supermicro expone vulnerabilidad crítica. Mekotio, Grandoreiro y Red Mongoose amenazan bancos en América Latina. Detalles en el próximo listado de noticias."
🗞️ ÚLTIMAS NOTICIAS EN SEGURIDAD INFORMÁTICA 🔒
====| 🔥 LO QUE DEBES SABER HOY 15/07/24 📆 |====
¡Claro que sí! Aquí tienes las noticias optimizadas de las últimas 24 horas en seguridad informática:
"""
🔒 CONFERENCE DRAGONJAR 2024
El DragonJAR Security Conference se llevará a cabo los días 26 y 27 de septiembre de 2024, en Bogotá, Colombia. ¡Descubre la charla "Explorando la ciberseguridad ofensiva en tecnologías aeroespaciales y satélites" de Romel Marin Córdoba! Inscríbete ya para explorar vulnerabilidades y técnicas de mitigación en sistemas aeroespaciales y satelitales. 👉 https://djar.co/WIKf0
🛡️ AT&T PAGÓ A UN HACKER $370,000 PARA BORRAR REGISTROS TELEFÓNICOS ROBADOS
Un investigador de seguridad reveló que la única copia de los registros de llamadas y mensajes de texto de "casi todos" los clientes de AT&T ha sido eliminada, pero aún pueden existir riesgos. No te pierdas este impactante suceso. 👉 https://djar.co/HDS2
🔐 BSIDES LAS VEGAS
BSides Las Vegas es una entidad sin fines de lucro enfocada en impulsar la industria de la seguridad de la información y fomentar la comunidad. Descubre más sobre esta importante organización. 👉 https://djar.co/zwrnKe
🔓 MOTHERBOARDS DE SUPERMICRO VULNERABLES A FALLA RCE CRÍTICA (CVE-2024-36435)
Supermicro Computer, reconocido proveedor de soluciones de servidores y placas base, ha expuesto una vulnerabilidad crítica de seguridad (CVE-2024-36435). Mantente al tanto de este relevante aviso. 👉 https://djar.co/rQKTfm
🚨 MSpy VUELVE A SER VÍCTIMA DE UNA BRECHA DE SEGURIDAD
Además: los routers Velops tienen debilidades con texto sin formato; todo apunta a un patrón oscuro; Internet Explorer resurge y más. Entérate de los detalles aquí. 👉 https://djar.co/ogN1O
🦠 TROYANOS #MEKOTIO, #GRANDOREIRO Y RED MONGOOSE AMENAZAN A BANCOS Y USUARIOS EN AMÉRICA LATINA
¡Precaución en la región! Se reporta actividad maliciosa de los troyanos #Mekotio, #Grandoreiro y Red Mongoose dirigida a bancos y usuarios en América Latina. Infórmate sobre esta amenaza latente. 👉 https://djar.co/O1LA
🌐 CLOUDFLARE BYPASS RESULTA EN RXSS EN MICROSOFT
Har Har Mahadev🔱. El investigador de seguridad Prince Roy, también conocido como royzsec, comparte su hallazgo sobre [Cross Site Scripting] en el dominio de Microsoft al evadir... Descubre más detalles sobre este intrigante descubrimiento. 👉 https://djar.co/LaEM2
"""
Grandoreiro Banking Trojan Resurfaces, Targeting Over 1,500 Banks Worldwide
https://thehackernews.com/2024/05/grandoreiro-banking-trojan-resurfaces.html #Cybercrime #Malware #Trojan #BankingTrojan #Grandoreiro
Grandoreiro, el troyano bancario, vuelve más fuerte que nunca https://blog.elhacker.net/2024/05/grandoreiro-el-troyano-bancario-vuelve.html #grandoreiro #bancario #Malware #troyano
Banking #malware #Grandoreiro returns after police disruption
Malware-as-a-service (MaaS) rented by threat actors and reworked to be more evasive and effective.
#phishing methods/lures are diverse, but many entice a target to click on a link which triggers the download of an executable that triggers the Grandoreiro loader.
Remember, if it looks (or sounds) icky, then no clicky! Additionally, always login to your bank account from the official app/domain to check statements, tax documents, or view invoices.
Grandoreiro Banking Trojan is Back With Major Updates – Source: www.infosecurity-magazine.com https://ciso2ciso.com/grandoreiro-banking-trojan-is-back-with-major-updates-source-www-infosecurity-magazine-com/ #rssfeedpostgeneratorecho #InfoSecurityMagazine #InfosecurityMagazine #CyberSecurityNews #Grandoreiro #Banking
Grandoreiro Banking Trojan Resurfaces, Targeting Over 1,500 Banks Worldwide – Source:thehackernews.com https://ciso2ciso.com/grandoreiro-banking-trojan-resurfaces-targeting-over-1500-banks-worldwide-sourcethehackernews-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #TheHackerNews #Grandoreiro #Banking
Cinco detenidos por robar 3,5 millones de euros con el troyano bancario Grandoreiro https://blog.elhacker.net/2024/03/5-detenidos-por-robar-3-coma-5-millones-troyano-bancario-grandoreiro.html #grandoreiro #bancario #interpol #troyano
España participa en una operación mundial para desarticular el troyano bancario Grandoreiro https://blog.elhacker.net/2024/01/espana-participa-en-una-operacion-desarticular-troyano-bancario-grandoreiro.html #grandoreiro #eset #dga
Hola Espana: ‘Grandoreiro’ Trojan Targets Global Banking Customers – Source: www.proofpoint.com https://ciso2ciso.com/hola-espana-grandoreiro-trojan-targets-global-banking-customers-source-www-proofpoint-com/ #ProofpointThreatInsights #rssfeedpostgeneratorecho #CyberSecurityNews #Grandoreiro #Proofpoint #Espana
A fresh #grandoreiro complete with initial email:
https://app.any.run/tasks/d8906703-56da-446c-ad4c-a43c8885b666/
Some fresh #grandoreiro at:
https://soluttionacorreougr.westus3.cloudapp[.azure[.com
c2: http://18.229.136[.]62:26978/NdtTOpdaaMd.xml
https://app.any.run/tasks/78d2c46f-2627-4b9b-89ed-e44c12362dee
Ongoing #Grandoreiro trojan #banker campaign targeting #Chile.
If victim's IP is out of Chile, there is a 403. For Chileans IPs it drops a malicious MSI with a random filename.
Extracted payload ->
28728fc47ec7d920830d036c5a9221ab *Binary.nmpDbaW.dll_1
original MSI: 0bd958b0c88d3614f563ea50f97c2121 *FOSKP89XAE.msi
Tx for the headsup, Ewald!
For the first time we are seeing an #Android banking #trojan that has #ScreenRecording and #keylogging as the main strategy to harvest #LoginCredentials in an automated and scalable way, While banking #malware such as #MysteryBot, #Grandoreiro, #Banker.BR, and #Vizom have traditionally relied on #OverlayAttacks traditionally.