Grandoreiro Banking Trojan is back and targets banks worldwide
ID: f4d5010d-f2ff-5ba8-9c45-3b6dc277edaf
STIX ID: report--f4d5010d-f2ff-5ba8-9c45-3b6dc277edaf
Feed Name: Security Affairs
Threat Score
Grandoreiro, a modular banking trojan, resumed operations in March 2024 and is targeting over 1,500 banks across more than 60 countries with a large, evasive loader (bloated >100MB, CAPTCHA, sandbox checks), updated DGA and string decryption, Outlook-based spreading, persistence via the Windows registry, and multiple exfiltration mechanisms—indicating a high-risk, globally expanding malware-as-a-service campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
