EXECUTIVE SUMMARY
Researchers have been tracking significant phishing campaigns distributing the Grandoreiro banking trojan. These campaigns, likely operated as Malware-as-a-Service (MaaS), have demonstrated notable updates in malware functionality, including string decryption and domain generating algorithm (DGA). Moreover, the latest variant of Grandoreiro exhibits a concerning ability to utilize Microsoft Outlook clients on infected hosts for spreading phishing emails. Targeting over 1500 global banks across 60 countries, including regions in Latin America, Africa, Europe, and the Indo-Pacific, these campaigns signify a strategic shift in the deployment of Grandoreiro, with impersonations extending to government entities in Mexico, Argentina, and South Africa.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
Researchers have been tracking significant phishing campaigns distributing the Grandoreiro banking trojan. These campaigns, likely operated as Malware-as-a-Service (MaaS), have demonstrated notable updates in malware functionality, including string decryption and domain generating algorithm (DGA). Moreover, the latest variant of Grandoreiro exhibits a concerning ability to utilize Microsoft Outlook clients on infected hosts for spreading phishing emails. Targeting over 1500 global banks across 60 countries, including regions in Latin America, Africa, Europe, and the Indo-Pacific, these campaigns signify a strategic shift in the deployment of Grandoreiro, with impersonations extending to government entities in Mexico, Argentina, and South Africa.[emaillocker id="1283"]
Grandoreiro is a multi-component banking trojan, likely operating as MaaS, with capabilities for phishing campaigns impersonating various government entities. The variant showcases advancements in string decryption and DGA calculation algorithms, enabling the creation of multiple C2 domains per day. Notably, Grandoreiro leverages infected hosts' Microsoft Outlook clients to perpetuate phishing campaigns. Its infection chain begins with a custom loader, verifying victims and collecting basic system information for profiling. The trojan establishes persistence via the Windows registry and targets over 1500 global banking applications. Employing a sophisticated DGA, Grandoreiro dynamically generates C2 domains, facilitating communication with its operators. Moreover, it supports a wide range of remote-control commands, file operations, and spamming functionalities, including harvesting email addresses from Outlook clients and sending out phishing emails.
The evolution of Grandoreiro represents a notable shift in cybercriminal strategies, with a broader geographical reach and increased sophistication. As these campaigns continue to expand globally, organizations must remain vigilant against phishing attempts and monitor for indicators of compromise. Implementing security measures such as network traffic monitoring, DNS blocking, and registry key oversight is essential to mitigate the risk posed by this pervasive banking trojan.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Initial Access | T1566 | Phishing |
| T1189 | Drive-by Compromise | |
| Execution | T1204 | User Execution |
| T1059 | Command and Scripting Interpreter | |
| T1053 | Scheduled Task/Job | |
| Persistence | T1543 | Create or Modify System Process |
| Defense Evasion | T1036 | Masquerading |
| T1027 | Obfuscated Files or Information | |
| T1564 | Hide Artifacts | |
| T1055 | Process Injection | |
| T1497 | Virtualization/Sandbox Evasion | |
| Credential Access | T1555 | Credentials from Password Stores |
| Discovery | T1082 | System Information Discovery |
| T1012 | Query Registry | |
| T1087 | Account Discovery | |
| T1057 | Process Discovery | |
| Collection | T1056 | Input Capture |
| T1005 | Data from Local System | |
| T1025 | Data from Removable Media | |
| T1119 | Automated Collection | |
| T1560 | Archive Collected Data | |
| Lateral Movement | T1021 | Remote Services |
| Command and Control | T1132 | Data Encoding |
| T1104 | Multi-Stage Channels | |
| T1105 | Ingress Tool Transfer | |
| T1071 | Application Layer Protocol | |
| T1102 | Web Service | |
| Exfiltration | T1041 | Exfiltration Over C2 Channel |
| T1048 | Exfiltration Over Alternative Protocol | |
| T1052 | Exfiltration Over Physical Medium |
REFERENCES:
The following reports contain further technical details:
[/emaillocker]