logo

Grandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android Users

ID: c9c26856-0350-51b0-adea-0b0236e51727

STIX ID: report--c9c26856-0350-51b0-adea-0b0236e51727

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-05-27

Date Updated: 2026-05-28

Author: [email protected] (The Hacker News)

...
...

WatchGuard and ESET report two active campaigns: Grandoreiro, a long-running Windows banking trojan leveraging DLL side-loading, WebRTC (STUN/ICE) for covert peer-to-peer communications and phishing-based distribution to target financial institutions in Portugal, Spain and Mexico; and BTMOB, an Android RAT-as-a-service distributed via phishing and fake app stores that abuses Android accessibility to capture credentials, screenshots, keystrokes and enable remote control, with a commercial builder, leaked source, and active underground sales increasing the risk of wider abuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.