Hackers Use Grandoreiro Malware to Target Portuguese Banks and Latin American Companies
ID: 44d607b4-b953-58cc-9d1f-8cbd6858cd6f
STIX ID: report--44d607b4-b953-58cc-9d1f-8cbd6858cd6f
Feed Name: cybersecurityNews.com
The report describes resurgent Grandoreiro banking-trojan campaigns that use phishing to deliver malicious DLL side-loading payloads and obfuscated VBS, leveraging cloud platforms (Google Cloud, Microsoft Azure, Amazon) and geofenced fake pages to blend in and evade detection; the malware performs credential theft, keylogging and banking overlays against banks and businesses across Portugal, Spain, Mexico and Latin America, and the report includes IoCs and detection/mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
