logo

A Look Back: The Evolution of Latin American eCrime Malware in 2024

ID: c92f35d6-69ec-57a4-8b86-1a40e327bf77

STIX ID: report--c92f35d6-69ec-57a4-8b86-1a40e327bf77

Feed Name: Crowdstrike Blog

Threat Score
78/100

Date Published: 2024-12-16

Date Updated: 2026-04-27

Author: Kevin Ratto

...
...

This report analyzes Kiron (Grandoreiro) banking trojan activity in 2024, documenting delivery via NestoLoader (JPHP), a shift from Delphi to a Rust-based downloader, embedded AES/XOR-encrypted payloads, DGA use, operator-specific prefixes (z and pkc) targeting financial institutions across Latin America and parts of Europe, new browser-stealer extension capabilities that exfiltrate cookies and email addresses, enhanced obfuscation (Base64+XOR+PRNG), and operational overlap with SAMBA SPIDER/Mispadu, providing multiple IOCs (domains, IPs, hardcoded keys) indicative of active, sophisticated eCrime campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.