logo

Hackers Use Grandoreiro Malware to Target Portuguese Banks and Latin American Companies

ID: 44d607b4-b953-58cc-9d1f-8cbd6858cd6f

STIX ID: report--44d607b4-b953-58cc-9d1f-8cbd6858cd6f

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-05-27

Date Updated: 2026-05-28

Author: Tushar Subhra Dutta

...
...

The report describes resurgent Grandoreiro banking-trojan campaigns that use phishing to deliver malicious DLL side-loading payloads and obfuscated VBS, leveraging cloud platforms (Google Cloud, Microsoft Azure, Amazon) and geofenced fake pages to blend in and evade detection; the malware performs credential theft, keylogging and banking overlays against banks and businesses across Portugal, Spain, Mexico and Latin America, and the report includes IoCs and detection/mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.