Grandoreiro Banking Trojan with New TTPs
ID: 1306d38d-2175-5634-9187-84aaf8a090fd
STIX ID: report--1306d38d-2175-5634-9187-84aaf8a090fd
Feed Name: Zscaler Security Research Blog
**Executive Summary:** Zscaler ThreatLabz observed an ongoing Grandoreiro banking trojan campaign (since June 2022) targeting organizations in Mexico and Spain across multiple sectors via Spanish-language spear-phishing; the campaign uses a Delphi-based loader with extensive anti-analysis controls (debugger/VM checks, process/window checks, Captcha), downloads a heavily padded ~400MB final payload, employs DGA and LatentBot-like C2 communications (ACTION=HELLO), and supports keylogging, web-injects, command execution and persistence. The report provides detailed infection chain analysis and numerous IOCs (URLs, domains, IPs, MD5s) useful for detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
