Grandoreiro Malware Campaign Hits Banks and Latin American Companies
ID: 12260aae-c946-59a6-b3f7-4a55c75dc06c
STIX ID: report--12260aae-c946-59a6-b3f7-4a55c75dc06c
Feed Name: Cyber Press
Threat Score
The Grandoreiro banking trojan has resurfaced in a phishing-driven campaign targeting banks and financial services across Portugal, Spain, Mexico and Latin America; attackers use DLL side-loading and obfuscated VBS to drop Delphi payloads, abuse cloud services (Dropbox, Mediafire, Contabo, Google Cloud, AWS, Azure), and employ advanced anti-analysis and evasion techniques, with known IOCs including 162.33.177.150 and domains uniaodownloadcnk.online and byethost.com.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
