Grandoreiro is a Brazilian banking trojan and associated cybercrime operation active since at least 2016. It is described as part of the Tetrade umbrella of Brazilian banking malware and has remained active despite law-enforcement disruptions and arrests in 2021 and 2024 in Spain, Brazil, and Argentina; reporting states only part of the gang was arrested and remaining operators continued developing malware and infrastructure. Grandoreiro has been characterized as a restricted malware-as-a-service offering available only to trusted partners. The threat actor initially operated primarily in Brazil and Latin America, later expanded into Europe in 2020, and is now described as a global financial threat. Reported targeting expanded from 900 banks in 40 countries in 2023 to 1,700 banks and 276 crypto wallets in 45 countries and territories in 2024. Countries specifically mentioned as affected or targeted include Mexico, Brazil, Spain, Argentina, the United States, the United Kingdom, India, South Africa, and Australia. One report also states some legacy variants are now focused mainly on Mexico. Grandoreiro primarily targets financial institutions and their customers. Campaigns commonly begin with phishing emails in the target country’s language, including lures such as tax-return or login-related messages, and some campaigns have also used Google Ads malvertising. Delivery chains described in the content include malicious PDFs redirecting to ZIP archives, Dropbox-hosted archives, MSI-based loaders, VBS-based loaders, and DLL side-loading using legitimate software. WatchGuard reported DLL side-loading campaigns targeting banks in Portugal through abuse of MinGW, FastStone Image Viewer, FreeMat, and AbiWord, using malicious DLLs such as mingw10.dll, libwebp.dll, libffi-6.dll, and libpng15.dll. Separate campaigns used geofenced fake pages on abused Contabo infrastructure and payload hosting on MediaFire. The malware is written in Delphi, with reports referencing Delphi 11 and Delphi 12 builds. It enables operators to monitor victim activity, remotely control victim machines, and perform fraudulent banking operations from the victim’s device to bypass banking security controls. Reported capabilities include credential theft, keylogging, Outlook keyword monitoring, spam sending through Outlook, clipboard replacement for cryptocurrency theft, and overlays that lock the victim’s screen and request OTPs, transaction passwords, SMS tokens, or other MFA information. Grandoreiro includes an operator console that lists victims when they browse targeted financial institution websites and supports remote desktop control. Since early 2022 it has used the RealThinClient SDK Delphi component for remote access and fraudulent operations, and it also includes a "Cloud VPS" gateway feature to hide operator IP addresses. The content describes extensive anti-analysis and evasion features. Grandoreiro gathers host and geolocation data, including via ip-api.com/json, and collects OS version, hostname, monitor details, keyboard layout, time zone, language, and mouse type. It checks for sandbox-related hostnames, usernames, paths, analyst tools, VMware artifacts, and debugging, including IsDebuggerPresent() and VMware I/O port checks. It searches for numerous security products and, in newer campaigns, added CAPTCHA-based sandbox evasion and expanded analysis-tool detection. It also uses binary padding with oversized resources to evade sandboxing, moved more anti-debugging logic into first-stage loaders, and in some cases avoids downloading payloads when the system language is English. WatchGuard also reported anti-debugging techniques including division by zero and UD2 instructions. Recent reporting states Grandoreiro evolved its codebase after operator arrests into lighter fragmented versions, strengthened string and configuration protection with multilayer encryption, and added three domain generation algorithms for C2. WatchGuard observed campaigns using WebRTC-related protocols such as STUN and ICE, as well as integrations involving Google Cloud Pub/Sub, Azure MQTT, Amazon MQTT, and the Binance API. The actor is also reported to abuse legitimate signed binaries and legitimate services to blend malicious traffic with normal activity. Known alias in the provided content: grandoreiro.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
52 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated banking trojan group conducting phishing-led campaigns that deliver Grandoreiro via DLL side-loading and malicious VBS loaders, targeting banks, financial services customers, SMBs, and users in Portugal, Spain, Mexico, and Latin America while abusing legitimate cloud and hosting services.
Grandoreiro is a cybercriminal group operating primarily in Brazil, known for targeting local victims with banking malware.
Financially motivated banking-trojan activity (active since at least 2017) that expanded beyond Latin America/Spanish-speaking regions to broader global targeting in 2024; uses phishing and social engineering to deliver a downloader and then steals banking funds, including prompting victims for MFA codes via fake dialogs.
Brazilian cybercriminal group/operators behind the Grandoreiro banking trojan, running global banking-fraud campaigns against banks and crypto-wallet users, continuously evolving malware, infrastructure, and anti-detection capabilities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.