Description
Grandoreiro is a Latin American banking trojan with the goal of stealing sensitive banking information, and it commonly targets customers of banks in Brazil, Mexico, Spain, and Peru. It arrives through spam emails that lead to fake installer pages, and it overlays fake windows on banking sites to capture credentials and manipulate transactions. The family's operators run it as a managed service for regional fraud crews, and its code base has forked into related Latin American bankers.
Stats
- First seen
- May 2022
- Last seen
- October 2026
MITRE ATT&CK techniques
43 techniques across 11 tactics.
TA0002 Execution
TA0003 Persistence
TA0004 Privilege Escalation
TA0005 Stealth
TA0006 Credential Access
TA0007 Discovery
TA0009 Collection
TA0011 Command and Control
TA0010 Exfiltration
- T1041Exfiltration Over C2 Channel
Alert name variants
| Alert Name |
|---|
| Archive-ZIP.Trojan.Grandoreiro |
| Binary.Malware.Grandoreiro |
| Binary.Trojan.Grandoreiro |
| ByteCode-MSIL.Trojan.Grandoreiro |
| Gen:Variant.Grandoreiro.1 |
| Gen:Variant.Grandoreiro.2 |
| Script-WScript.Trojan.Grandoreiro |
| Shortcut.Trojan.Grandoreiro |
| Trojan.Grandoreiro.1 |
| Trojan.Grandoreiro.A |
