logo

Grandoreiro banking malware disrupted – Week in security with Tony Anscombe

ID: 7c0c0d62-1b5f-54fc-a87f-428e1c6774d5

STIX ID: report--7c0c0d62-1b5f-54fc-a87f-428e1c6774d5

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
70/100

Date Published: 2024-02-02

Date Updated: 2026-05-01

...
...

Law enforcement in Brazil, assisted by ESET, Interpol, the Spanish Police and Caixa Bank, disrupted the Grandoreiro banking trojan infrastructure. Grandoreiro — active since at least 2017 across Brazil, Mexico, Spain and Argentina — used screen blocking, keystroke logging, simulated mouse/keyboard activity and fake pop-ups to commit banking fraud, causing millions in losses; ESET provided technical analysis and known C&C domains and IP addresses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.