logo

Grandoreiro Malware Campaign Hits Banks and Latin American Companies

ID: 12260aae-c946-59a6-b3f7-4a55c75dc06c

STIX ID: report--12260aae-c946-59a6-b3f7-4a55c75dc06c

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-05-27

Date Updated: 2026-05-27

Author: Varshini

...
...

The Grandoreiro banking trojan has resurfaced in a phishing-driven campaign targeting banks and financial services across Portugal, Spain, Mexico and Latin America; attackers use DLL side-loading and obfuscated VBS to drop Delphi payloads, abuse cloud services (Dropbox, Mediafire, Contabo, Google Cloud, AWS, Azure), and employ advanced anti-analysis and evasion techniques, with known IOCs including 162.33.177.150 and domains uniaodownloadcnk.online and byethost.com.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.