Grandoreiro is a Brazilian financially motivated cybercrime operation centered on a long-running banking trojan active since at least 2016. It is commonly associated with the Tetrade cluster of Brazilian banking malware and has evolved from a Latin America-focused threat into a global banking-fraud operation targeting financial institutions and users across dozens of countries. Despite law-enforcement disruptions and arrests in 2021 and 2024, the group has continued operating, with remaining operators maintaining and developing new malware branches and infrastructure. Grandoreiro primarily targets banks and other financial entities, with campaigns documented against institutions in Latin America and Europe and broader victimization reported worldwide. The malware has also expanded to target cryptocurrency wallets. Activity has been observed affecting countries including Mexico, Brazil, Spain, Argentina, Portugal, the United States, the United Kingdom, India, South Africa, and Australia. Initial access is typically achieved through phishing emails in the victim’s local language, sometimes supplemented by malvertising. Delivery chains have used archive-based downloaders, MSI and VBS loaders, and fake update or verification prompts to induce execution. The actor is well known for extensive use of DLL sideloading with legitimate signed applications, as well as oversized padded binaries and CAPTCHA-style checks to frustrate automated analysis. Once installed, Grandoreiro performs broad host profiling and anti-analysis checks, including geolocation validation, debugger and virtualization detection, security-product discovery, and environment-based execution gating. The malware has progressively shifted anti-debugging and evasion logic into earlier loader stages and uses layered string and configuration protection. Recent versions also employ multiple domain generation algorithms and fragmented codebases to improve resilience and complicate disruption. Operationally, Grandoreiro functions as a banking trojan with remote-access capabilities that allow operators to monitor victim activity and intervene when targeted banking sessions occur. It supports remote desktop control, keylogging, Outlook monitoring, and other post-compromise functions. Fraud-enablement features include screen overlays to solicit one-time passwords, transaction passwords, or SMS tokens; in-session manipulation to facilitate fraudulent banking transactions; and clipboard replacement aimed at cryptocurrency theft. The malware is designed to abuse the victim’s own device and session context to bypass banking security controls and anti-fraud mechanisms, including behavior-based defenses. Reporting has described Grandoreiro as operating in a restricted malware-as-a-service model limited to trusted partners rather than openly marketed on criminal forums. Overall, Grandoreiro is best characterized as a mature Brazilian banking-malware ecosystem focused on credential theft, session abuse, and direct financial fraud against banks and their customers.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
57 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated banking trojan group conducting phishing-led campaigns that deliver Grandoreiro via DLL side-loading and malicious VBS loaders, targeting banks, financial services customers, SMBs, and users in Portugal, Spain, Mexico, and Latin America while abusing legitimate cloud and hosting services.
Grandoreiro is a cybercriminal group operating primarily in Brazil, known for targeting local victims with banking malware.
Financially motivated banking-trojan activity (active since at least 2017) that expanded beyond Latin America/Spanish-speaking regions to broader global targeting in 2024; uses phishing and social engineering to deliver a downloader and then steals banking funds, including prompting victims for MFA codes via fake dialogs.
Brazilian cybercriminal group/operators behind the Grandoreiro banking trojan, running global banking-fraud campaigns against banks and crypto-wallet users, continuously evolving malware, infrastructure, and anti-detection capabilities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.