ESET takes part in global operation to disrupt the Grandoreiro banking trojan
ID: 13cb2493-4946-5aa1-a22f-f0fcd8136771
STIX ID: report--13cb2493-4946-5aa1-a22f-f0fcd8136771
Feed Name: WeLiveSecurity (ESET Research)
ESET’s report analyzes the Grandoreiro Latin‑American banking trojan, documenting its domain generation algorithm (DGA), RTC‑Portal based C2 protocol, victimology metrics (hundreds of active victims daily and ~114 new unique victims/day), clusters of DGA configurations and IP overlaps, and provides IoCs (file hashes and C2 IPs). The analysis supported a disruption operation with the Federal Police of Brazil that identified and led to arrests of individuals operating the botnet; the report includes MITRE ATT&CK mappings and operational details to aid detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
