logo

Authorities Dismantle Grandoreiro Banking Malware Operation

ID: d85d56d8-3f29-5426-a8b7-878c53ebe249

STIX ID: report--d85d56d8-3f29-5426-a8b7-878c53ebe249

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2024-03-21

Date Updated: 2026-04-22

Author: Guru baran

...
...

Group-IB, INTERPOL, and Brazilian and Spanish law enforcement collaborated to analyze and dismantle the Grandoreiro banking trojan operation, using collected malware samples (2020–2022) to track shifting command-and-control infrastructure and identify an active C2 server that enabled arrests of five administrators in January 2024; the trojan used phishing, keystroke logging, screen sharing, simulated clicks and deceptive pop-ups to steal banking credentials and siphon funds through money mule networks, with documented losses around EUR 3.5M and potential larger impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.