logo

'Grandoreiro' Malware Resurfaces With Mexico Campaign

ID: f650e5e2-239b-5c02-8939-731888c5278f

STIX ID: report--f650e5e2-239b-5c02-8939-731888c5278f

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2026-08-20

Date Updated: 2026-08-21

Author: Jai Vijayan

...
...

The Grandoreiro banking Trojan continues to be actively used in a new campaign targeting primarily Latin American banking customers (notably Mexico) by delivering a 12-year-old payload via spammed ZIP archives that include a repurposed legitimate Duplicate Files Finder application and DLL sideloading; the loader implements extensive anti-analysis and anti-forensics checks before fetching the main payload, and telemetry shows some victims in North America and Europe as well.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.