logo

Grandoreiro Banking Trojan with New TTPs

ID: 1306d38d-2175-5634-9187-84aaf8a090fd

STIX ID: report--1306d38d-2175-5634-9187-84aaf8a090fd

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

**Executive Summary:** Zscaler ThreatLabz observed an ongoing Grandoreiro banking trojan campaign (since June 2022) targeting organizations in Mexico and Spain across multiple sectors via Spanish-language spear-phishing; the campaign uses a Delphi-based loader with extensive anti-analysis controls (debugger/VM checks, process/window checks, Captcha), downloads a heavily padded ~400MB final payload, employs DGA and LatentBot-like C2 communications (ACTION=HELLO), and supports keylogging, web-injects, command execution and persistence. The report provides detailed infection chain analysis and numerous IOCs (URLs, domains, IPs, MD5s) useful for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.