'Grandoreiro' Malware Resurfaces With Mexico Campaign
ID: f650e5e2-239b-5c02-8939-731888c5278f
STIX ID: report--f650e5e2-239b-5c02-8939-731888c5278f
Feed Name: Dark Reading
Threat Score
The Grandoreiro banking Trojan continues to be actively used in a new campaign targeting primarily Latin American banking customers (notably Mexico) by delivering a 12-year-old payload via spammed ZIP archives that include a repurposed legitimate Duplicate Files Finder application and DLL sideloading; the loader implements extensive anti-analysis and anti-forensics checks before fetching the main payload, and telemetry shows some victims in North America and Europe as well.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
