Threat Advisory

Grandoreiro Malware Campaign Abuses Files Software with Advanced Evasion Methods

Threat: Malware Campaign
Targeted Region: Global
Threat Actor Region: Finance & Banking
Criticality: High
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Grandoreiro, a long-running banking trojan targeting users across Latin America, has continued its operations through updated infection techniques and improved evasion mechanisms. The malware has historically relied on phishing campaigns and social engineering tactics to compromise victims, with showing a renewed focus on Mexico. The latest campaign demonstrates an increased emphasis on stealth by abusing legitimate software applications to execute malicious payloads while attempting to avoid security detection.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Grandoreiro, a long-running banking trojan targeting users across Latin America, has continued its operations through updated infection techniques and improved evasion mechanisms. The malware has historically relied on phishing campaigns and social engineering tactics to compromise victims, with showing a renewed focus on Mexico. The latest campaign demonstrates an increased emphasis on stealth by abusing legitimate software applications to execute malicious payloads while attempting to avoid security detection.[emaillocker id="1283"]

The campaign delivers Grandoreiro through an archive containing decoy documents and a malicious loader that relies on DLL sideloading to execute the malware. Attackers abuse the legitimate Duplicate Files Finder application by placing a malicious DLL within the same directory, allowing the trusted executable to load the malicious component through the normal Windows DLL search process. The malware implements multiple anti-analysis mechanisms, including sandbox detection, virtual machine artifact checks, process blacklisting, environment profiling, and system validation routines to avoid execution in research environments. It also collects host information, checks installed applications, identifies geographic details, and communicates with command-and-control infrastructure using encrypted requests to retrieve additional payloads.

It demonstrates the malware’s continued adaptation through trusted application abuse, advanced evasion techniques, and multi-stage execution methods. By combining DLL sideloading with anti-analysis capabilities, attackers aim to reduce detection opportunities and maintain effective control over infected systems. Although activity levels have declined compared to previous operations, Grandoreiro remains an active threat targeting users in Latin America, particularly through stealth-focused campaigns designed to bypass traditional security defenses.

 

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1566.003 Phishing Spearphishing via Service
Persistence T1547.001 Boot or Logon Autostart Execution Registry Run Keys / Startup Folder
Stealth T1027.013 Obfuscated Files or Information Encrypted/Encoded File
Command and control T1071.001 Application Layer Protocol Web Protocols

 

MBC MAPPING:

Objective Behavior ID Behavior
Anti-Behavioral Analysis B0003 Dynamic Analysis Evasion
Anti-Static Analysis E1027 Obfuscated Files or Information
Command and Control B0030 C2 Communication
Execution E1204 User Execution
B0023 Install Additional Program

 

REFERENCES:

The following reports contain further technical details:

https://www.darkreading.com/cyberattacks-data-breaches/grandoreiro-resurfaces-mexico-campaign

https://www.acronis.com/en/tru/posts/grandoreiro-goes-north-from-brazil-to-mexico-with-a-new-dll-sideloading-campaign/

[/emaillocker]
crossmenu