Authorities Dismantle Grandoreiro Banking Malware Operation
ID: d85d56d8-3f29-5426-a8b7-878c53ebe249
STIX ID: report--d85d56d8-3f29-5426-a8b7-878c53ebe249
Feed Name: GBHackers
Group-IB, INTERPOL, and Brazilian and Spanish law enforcement collaborated to analyze and dismantle the Grandoreiro banking trojan operation, using collected malware samples (2020–2022) to track shifting command-and-control infrastructure and identify an active C2 server that enabled arrests of five administrators in January 2024; the trojan used phishing, keystroke logging, screen sharing, simulated clicks and deceptive pop-ups to steal banking credentials and siphon funds through money mule networks, with documented losses around EUR 3.5M and potential larger impact.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
