EXECUTIVE SUMMARY:
Grandoreiro, a long-running banking trojan targeting users across Latin America, has continued its operations through updated infection techniques and improved evasion mechanisms. The malware has historically relied on phishing campaigns and social engineering tactics to compromise victims, with showing a renewed focus on Mexico. The latest campaign demonstrates an increased emphasis on stealth by abusing legitimate software applications to execute malicious payloads while attempting to avoid security detection.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
Grandoreiro, a long-running banking trojan targeting users across Latin America, has continued its operations through updated infection techniques and improved evasion mechanisms. The malware has historically relied on phishing campaigns and social engineering tactics to compromise victims, with showing a renewed focus on Mexico. The latest campaign demonstrates an increased emphasis on stealth by abusing legitimate software applications to execute malicious payloads while attempting to avoid security detection.[emaillocker id="1283"]
The campaign delivers Grandoreiro through an archive containing decoy documents and a malicious loader that relies on DLL sideloading to execute the malware. Attackers abuse the legitimate Duplicate Files Finder application by placing a malicious DLL within the same directory, allowing the trusted executable to load the malicious component through the normal Windows DLL search process. The malware implements multiple anti-analysis mechanisms, including sandbox detection, virtual machine artifact checks, process blacklisting, environment profiling, and system validation routines to avoid execution in research environments. It also collects host information, checks installed applications, identifies geographic details, and communicates with command-and-control infrastructure using encrypted requests to retrieve additional payloads.
It demonstrates the malware’s continued adaptation through trusted application abuse, advanced evasion techniques, and multi-stage execution methods. By combining DLL sideloading with anti-analysis capabilities, attackers aim to reduce detection opportunities and maintain effective control over infected systems. Although activity levels have declined compared to previous operations, Grandoreiro remains an active threat targeting users in Latin America, particularly through stealth-focused campaigns designed to bypass traditional security defenses.
THREAT PROFILE:
| Tactic | Technique Id | Technique | Sub-technique |
| Initial access | T1566.003 | Phishing | Spearphishing via Service |
| Persistence | T1547.001 | Boot or Logon Autostart Execution | Registry Run Keys / Startup Folder |
| Stealth | T1027.013 | Obfuscated Files or Information | Encrypted/Encoded File |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
MBC MAPPING:
| Objective | Behavior ID | Behavior |
| Anti-Behavioral Analysis | B0003 | Dynamic Analysis Evasion |
| Anti-Static Analysis | E1027 | Obfuscated Files or Information |
| Command and Control | B0030 | C2 Communication |
| Execution | E1204 | User Execution |
| B0023 | Install Additional Program |
REFERENCES:
The following reports contain further technical details:
https://www.darkreading.com/cyberattacks-data-breaches/grandoreiro-resurfaces-mexico-campaign
[/emaillocker]