logo

Grandoreiro Banking Trojan Resurfaces, Targeting Over 1,500 Banks Worldwide

ID: 84c0d089-a41b-5862-9df2-bbdea1c3ad85

STIX ID: report--84c0d089-a41b-5862-9df2-bbdea1c3ad85

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-05-19

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

A revived Grandoreiro banking-trojan campaign has been active globally since March 2024, using large-scale phishing to deliver a padded loader and the banking trojan to targets across 60+ countries and 1,500+ banks; the malware includes a reworked DGA, improved string decryption, geolocation checks to avoid certain countries, and a new Outlook-based spamming module to propagate via infected mailboxes, and researchers also observed a substantially rewritten fork dubbed "NewGrandoreiro."

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.