logo

Grandoreiro Banking Trojan is back and targets banks worldwide

ID: f4d5010d-f2ff-5ba8-9c45-3b6dc277edaf

STIX ID: report--f4d5010d-f2ff-5ba8-9c45-3b6dc277edaf

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2024-05-20

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Grandoreiro, a modular banking trojan, resumed operations in March 2024 and is targeting over 1,500 banks across more than 60 countries with a large, evasive loader (bloated >100MB, CAPTCHA, sandbox checks), updated DGA and string decryption, Outlook-based spreading, persistence via the Windows registry, and multiple exfiltration mechanisms—indicating a high-risk, globally expanding malware-as-a-service campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.