logo

ESET takes part in global operation to disrupt the Grandoreiro banking trojan

ID: 13cb2493-4946-5aa1-a22f-f0fcd8136771

STIX ID: report--13cb2493-4946-5aa1-a22f-f0fcd8136771

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
72/100

Date Published: 2024-01-30

Date Updated: 2026-05-01

...
...

ESET’s report analyzes the Grandoreiro Latin‑American banking trojan, documenting its domain generation algorithm (DGA), RTC‑Portal based C2 protocol, victimology metrics (hundreds of active victims daily and ~114 new unique victims/day), clusters of DGA configurations and IP overlaps, and provides IoCs (file hashes and C2 IPs). The analysis supported a disruption operation with the Federal Police of Brazil that identified and led to arrests of individuals operating the botnet; the report includes MITRE ATT&CK mappings and operational details to aid detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.