Grandoreiro Banking Trojan Resurfaces, Targeting Over 1,500 Banks Worldwide
ID: 84c0d089-a41b-5862-9df2-bbdea1c3ad85
STIX ID: report--84c0d089-a41b-5862-9df2-bbdea1c3ad85
Feed Name: The Hacker News
A revived Grandoreiro banking-trojan campaign has been active globally since March 2024, using large-scale phishing to deliver a padded loader and the banking trojan to targets across 60+ countries and 1,500+ banks; the malware includes a reworked DGA, improved string decryption, geolocation checks to avoid certain countries, and a new Outlook-based spamming module to propagate via infected mailboxes, and researchers also observed a substantially rewritten fork dubbed "NewGrandoreiro."
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
