Grandoreiro Banking Trojan Returns With a DLL Sideloading Campaign
ID: 2b745c0d-b374-5271-9b48-ec3d77c3a9ff
STIX ID: report--2b745c0d-b374-5271-9b48-ec3d77c3a9ff
Feed Name: securityonline.info
Acronis researchers observed a renewed Grandoreiro banking-trojan campaign (May–June 2026) that delivers a malicious DLL via DLL sideloading of a renamed Duplicate Files Finder app, likely distributed in invoice-themed ZIP spam; the loader includes extensive sandbox/VM and analyst-evasion checks, resolves C2 via DoH to Google and retrieves a second-stage payload, and telemetry shows most detections in Mexico with additional victims in Spain, Peru and Argentina—Acronis provides IOCs and defensive guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
