Threat Advisory

Grandoreiro Banking Trojan Targeting Banks to Steal Data

Threat: Malware
Targeted Region: Mexico, Argentina & South Africa
Targeted Sector: Finance & Banking
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

Researchers have been tracking significant phishing campaigns distributing the Grandoreiro banking trojan. These campaigns, likely operated as Malware-as-a-Service (MaaS), have demonstrated notable updates in malware functionality, including string decryption and domain generating algorithm (DGA). Moreover, the latest variant of Grandoreiro exhibits a concerning ability to utilize Microsoft Outlook clients on infected hosts for spreading phishing emails. Targeting over 1500 global banks across 60 countries, including regions in Latin America, Africa, Europe, and the Indo-Pacific, these campaigns signify a strategic shift in the deployment of Grandoreiro, with impersonations extending to government entities in Mexico, Argentina, and South Africa.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

Researchers have been tracking significant phishing campaigns distributing the Grandoreiro banking trojan. These campaigns, likely operated as Malware-as-a-Service (MaaS), have demonstrated notable updates in malware functionality, including string decryption and domain generating algorithm (DGA). Moreover, the latest variant of Grandoreiro exhibits a concerning ability to utilize Microsoft Outlook clients on infected hosts for spreading phishing emails. Targeting over 1500 global banks across 60 countries, including regions in Latin America, Africa, Europe, and the Indo-Pacific, these campaigns signify a strategic shift in the deployment of Grandoreiro, with impersonations extending to government entities in Mexico, Argentina, and South Africa.[emaillocker id="1283"]

Grandoreiro is a multi-component banking trojan, likely operating as MaaS, with capabilities for phishing campaigns impersonating various government entities. The variant showcases advancements in string decryption and DGA calculation algorithms, enabling the creation of multiple C2 domains per day. Notably, Grandoreiro leverages infected hosts' Microsoft Outlook clients to perpetuate phishing campaigns. Its infection chain begins with a custom loader, verifying victims and collecting basic system information for profiling. The trojan establishes persistence via the Windows registry and targets over 1500 global banking applications. Employing a sophisticated DGA, Grandoreiro dynamically generates C2 domains, facilitating communication with its operators. Moreover, it supports a wide range of remote-control commands, file operations, and spamming functionalities, including harvesting email addresses from Outlook clients and sending out phishing emails.

The evolution of Grandoreiro represents a notable shift in cybercriminal strategies, with a broader geographical reach and increased sophistication. As these campaigns continue to expand globally, organizations must remain vigilant against phishing attempts and monitor for indicators of compromise. Implementing security measures such as network traffic monitoring, DNS blocking, and registry key oversight is essential to mitigate the risk posed by this pervasive banking trojan.

THREAT PROFILE:

Tactic Technique Id Technique
Initial Access T1566 Phishing
T1189 Drive-by Compromise
 Execution T1204 User Execution
T1059 Command and Scripting Interpreter
 T1053 Scheduled Task/Job
 Persistence  T1543 Create or Modify System Process
Defense Evasion T1036 Masquerading
T1027 Obfuscated Files or Information
T1564 Hide Artifacts
 T1055 Process Injection
T1497 Virtualization/Sandbox Evasion
Credential Access T1555 Credentials from Password Stores
Discovery  T1082 System Information Discovery
T1012 Query Registry
T1087 Account Discovery
T1057 Process Discovery
 Collection T1056 Input Capture
T1005 Data from Local System
T1025 Data from Removable Media
T1119 Automated Collection
T1560 Archive Collected Data
Lateral Movement T1021 Remote Services
Command and Control T1132 Data Encoding
T1104 Multi-Stage Channels
T1105 Ingress Tool Transfer
T1071 Application Layer Protocol
T1102 Web Service
Exfiltration T1041 Exfiltration Over C2 Channel
T1048 Exfiltration Over Alternative Protocol
T1052 Exfiltration Over Physical Medium

REFERENCES:

The following reports contain further technical details:

https://www.bleepingcomputer.com/news/security/banking-malware-grandoreiro-returns-after-police-disruption/#google_vignette

[/emaillocker]
crossmenu