logo

Banking malware Grandoreiro returns after police disruption

ID: 86f894ee-b792-5c96-b854-6e1c3aab9875

STIX ID: report--86f894ee-b792-5c96-b854-6e1c3aab9875

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-05-18

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

**Grandoreiro banking trojan resurfaces as a strengthened, MaaS-driven global phishing campaign** — After a January 2024 takedown effort, Grandoreiro has reportedly returned to large-scale operations since March 2024, targeting customers of roughly 1,500 banks across 60+ countries; the updated malware includes improved string decryption, a multi-seed domain generation algorithm, Outlook abuse to spread phishing, new persistence via Run registry keys, expanded command-and-control capabilities (remote control, file upload/download, keylogging, browser manipulation), and victim profiling to evade execution in certain countries and configurations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.