Hacking

New Grandoreiro Banking Malware Variants Bypass Anti-Fraud Measures

Published  ·  3 min read

Grandoreiro, a banking malware active since 2016, continues to evolve with new tactics aimed at bypassing anti-fraud measures. Despite law enforcement efforts, including recent arrests of some group members, the malware remains under active development. According to Kaspersky, "Only part of this gang was arrested: the remaining operators behind Grandoreiro continue attacking users all over the world, further developing new malware and establishing new infrastructure."

Recent variants of Grandoreiro feature several new techniques, including the use of a Domain Generation Algorithm (DGA) for Command-and-Control (C2) communications, Ciphertext Stealing (CTS) encryption, and mouse tracking. Additionally, lighter local versions have been seen, specifically targeting banking customers in Mexico.

Since its inception, Grandoreiro has expanded its geographic reach to Latin America and Europe, now targeting 1,700 financial institutions across 45 countries. While operating under a Malware-as-a-Service (MaaS) model, it appears to only be offered to select cybercriminals.

One major development this year involved the arrests of some group members, leading to the fragmentation of the malware's Delphi codebase. As a result, Kaspersky identified two distinct codebases in current campaigns: newer samples with updated code and older ones still targeting users in Mexico, focusing on customers of around 30 banks.

Distribution Methods

Grandoreiro is primarily spread via phishing emails, though some attacks have leveraged malicious ads served through Google. The infection chain typically begins with a ZIP file containing a legitimate file and an MSI loader that downloads and launches the malware.

In 2023 campaigns, Grandoreiro disguised itself as AMD External Data SSD drivers, with executable files as large as 390 MB to evade sandboxes and avoid detection.

Once installed, the malware collects host information, IP address data, and usernames. It halts execution if it detects certain strings like "John" or "WORK" in the username. It also searches for anti-malware solutions like Avast, Bitdefender, Kaspersky, and McAfee, as well as banking security software such as Topaz OFD and Trusteer.

Additionally, Grandoreiro checks for the presence of web browsers, email clients, VPNs, and cloud storage apps, monitoring user activity across these platforms. It can also act as a clipper, rerouting cryptocurrency transactions to wallets controlled by the attackers.

New Tactics

Some of the newer attack chains include a CAPTCHA barrier before executing the main payload, a tactic designed to bypass automated analysis. The latest versions of Grandoreiro also feature self-updating capabilities, keylogging, and Outlook integration for sending spam and monitoring specific keywords in Outlook emails.

The malware has introduced mouse tracking to mimic legitimate user behavior, aiming to bypass anti-fraud systems that rely on behavioral biometrics and machine learning.

Once credentials are stolen, attackers use transfer apps, cryptocurrency, or gift cards to cash out, often with the help of local money mules recruited through Telegram channels. These mules are typically paid between $200 to $500 per day.

Remote access to victim machines is provided via a Delphi-based tool called Operator, which tracks victims as they browse targeted financial websites.

Broader Threat Landscape

Brazilian banking trojans like Grandoreiro are an increasing international threat, filling gaps left by Eastern European gangs who have shifted focus to ransomware. The trend has been further underscored by recent campaigns, including Gecko Assault, which deploys two other banking malware families, Mispadu and Mekotio, targeting Windows users in Latin America (LATAM).

Additionally, Silver Oryx Blade, another banking trojan aimed at stealing financial information, has targeted Brazilian users through phishing emails impersonating HR departments and Brazil’s Ministry of Finance.

The ongoing evolution of Grandoreiro and similar malware demonstrates the adaptability of cybercriminals as they refine their techniques to overcome modern security solutions and anti-fraud measures.

Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067