Grandoreiro is a Brazilian banking trojan, active since at least 2016, commonly associated with the Brazilian banking malware cluster known as the “Tetrade.” It is a Delphi-based banking malware family designed to enable fraudulent banking operations by using the victim’s computer to bypass banking security controls. Reporting in the provided content states that it has targeted banks and financial institutions across Latin America, Europe, and globally, including Mexico, Brazil, Spain, Argentina, Portugal, and many other countries. Kaspersky reported that in 2024 it targeted 1,700 banks and 276 cryptocurrency wallets across 45 countries and territories.
Grandoreiro is primarily distributed through phishing campaigns. Observed delivery chains include malicious attachments, phishing emails containing URLs that lead to ZIP archives, tax-themed lures, malicious PDFs, MSI/HTA/EXE/VBS loaders, Dropbox- or MediaFire-hosted payloads, and campaigns using Azure- or Contabo-hosted redirect infrastructure. Multiple reports in the content describe DLL side-loading using legitimate software such as MinGW, FastStone Image Viewer, FreeMat, and AbiWord. Some campaigns used oversized padded binaries, fake Adobe Reader update prompts, CAPTCHA checks, geofencing, and anti-analysis logic to evade detection.
Its capabilities described in the content include keylogging, screen capture or screen-grabbing, web injection, command execution, desktop window manipulation, remote control of victim machines, self-updating, malicious URL lures, simulated mouse or keyboard movement, and clipboard capture. It can collect the username from the victim machine and enumerate installed security products, including Trusteer and Diebold Warsaw GAS Tecnologia protections. The malware has also been reported to monitor installed browsers, Outlook, VPN software, cloud storage tools, and cryptocurrency wallets, and to use overlays or fake banking screens to steal credentials, OTPs, transaction passwords, and other banking information during live sessions. Recent reporting also notes clipboard replacement for cryptocurrency theft and use of three DGAs for command-and-control domain generation.
The content links Grandoreiro to campaigns targeting banking customers and organizations, especially in Latin America and Europe, with specific references to Portugal, Spain, Mexico, and Argentina. Proofpoint attributed some campaigns to TA2725. The malware is repeatedly described as one of the most widespread banking trojans globally. Law-enforcement actions in 2021 and 2024 disrupted parts of its infrastructure and led to arrests in Spain, Brazil, and Argentina, but the content states that remaining operators continued development and operations.
Observed behaviors and indicators mentioned in the content include Registry storage of configuration under HKCU\Software\ using changing names such as %USERNAME% and ToolTech-RM; use of SSL in C2 communications; geolocation checks via hxxp://ip-api[.]com/json; campaign infrastructure including openingpdfdocxetc.southcentralus.cloudapp.azure.com, rwveebye.christiangabanna.com, uniaodownloadcnk[.]online, vmi<7-digit-number>[.]contaboserver[.]net, Dropbox and MediaFire delivery links, and IPs such as 139.162.3.243, 18[.]212[.]216[.]95:42195, 98[.]81[.]92[.]194:30154, and 162[.]33[.]177[.]150. File indicators explicitly cited include SHA-256 da21cb84f36e1ce6a90b69bddac50c4b28c9561913197c8f92f4dfe919102d74 and f2d850025dd7b65c44d979ec74a3f5a77e1c15b4070812be5656887cee95dc59. Kaspersky detection names in the content include HEUR:Trojan-Banker.Win32.Grandoreiro, Trojan-Downloader.OLE2.Grandoreiro, Trojan.PDF.Grandoreiro, and Trojan-Downloader.Win32.Grandoreiro.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A new version of Grandoreiro malware from TA2725 targets both Mexico and Spain. Previously this malware has only targeted victims in Brazil and Mexico.
In 2025, Brazilian-origin families such as Grandoreiro (part of the Tetrade group) stood out for their constant activity and global reach. Despite a major law enforcement disruption in early 2024, Grandoreiro remained active in 2025, re-emerging with updated variants and continuing to operate.
38 distinct techniques documented for this family, organized by ATT&CK tactic.
Their developers often distribute samples via phishing emails, sometimes casting a wide net and other times targeting specific individuals. These emails often masquerade as official correspondence related to tax or compliance matters, and occasionally attempt to impersonate government or tax agencies themselves.
In early 2022 campaigns, the malicious email included an attached PDF. As soon as the PDF is opened, the victim is prompted with a blurred image... When the victim clicks the button, they are redirected to a malicious web page which prompts them to download a ZIP file.
In 2022, a Grandoreiro variant was observed leveraging enhanced detection evasion techniques and had several new features: keylogging, automatically applying updates to itself, web injection, command execution...
A closer inspection reveals a rather simple but effective trick: a JavaScript redirection.
Inside the zip file... there was an EXE file, just like the good old times, accompanied by an “XML” file which was actually another executable.
Sandworm Team leveraged Microsoft Office attachments which contained malicious macros that were automatically executed once the user permitted them... APT29 has used various forms of spearphishing attempting to get a user to open attachments... DarkGate is distributed through phishing links to VBS or MSI objects requiring user interaction for execution.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
This growth is likely due to an artificial pattern that can be easily compressed for distribution, but expands upon decompression, potentially discouraging antivirus programs from scanning the file due to its size.
Grandoreiro utilizes a binary padding technique to inflate the size of the malicious files as a way to evade sandboxes.
the original sender is not “gob.mx” but rather someone else’s website... These emails often masquerade as official correspondence related to tax or compliance matters, and occasionally attempt to impersonate government or tax agencies themselves.
The content repeatedly describes malware and threat actors decoding, decrypting, deobfuscating, or unpacking payloads, strings, configuration data, commands, and C2 responses prior to execution or use.
using legitimate binaries that are digitally signed to run the malware.
The website says: “The content is not available on mobile devices. Please access it on a COMPUTER.” ... After changing the User-Agent header ... I was automatically being redirected to Google... after changing my VPN node and the User-Agent header once again to simulate Firefox on Windows, I was able to proceed with the infection chain.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
present a custom image (overlay) to ask the victim for extra information. These are usually OTPs (one-time passwords), transaction passwords or tokens received by SMS
In 2022, a Grandoreiro variant was observed leveraging enhanced detection evasion techniques and had several new features: keylogging... In 2024, Casabaneiro (Mekotio) was observed targeting financial systems... displaying the capabilities to produce fake banking pop-ups to capture banking credentials, capture screenshots, log keystrokes, and access clipboard data.
the malware is capturing user input patterns, particularly mouse movements... “Record for 5 seconds the client’s average mouse speed”
The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.
The content repeatedly describes malware and threat actors collecting usernames, identifying logged-in users, running whoami/query user/quser, checking whether the current user is an administrator, enumerating user sessions, and gathering account details from compromised hosts.
The malware takes a snapshot of currently executing processes in the system using the CreateToolhelp32Snapshot() Windows API and goes through the process list using Process32FirstW() and Process32NextW().
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
The website says: “The content is not available on mobile devices. Please access it on a COMPUTER.” ... After changing the User-Agent header ... I was automatically being redirected to Google... after changing my VPN node and the User-Agent header once again to simulate Firefox on Windows, I was able to proceed with the infection chain.
some Grandoreiro samples check whether the following programs are installed: CHROME.EXE; MSEDGE.EXE; FIREFOX.EXE; IEXPLORE.EXE; OUTLOOK.EXE... VeraCrypt; Nortonvpn; Adobe; OneDrive; Dropbox.
Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment.
One of these tasks is the use of the geolocation service http://ip-api.com/json to gather the target’s IP address location data.
present a custom image (overlay) to ask the victim for extra information. These are usually OTPs (one-time passwords), transaction passwords or tokens received by SMS
In 2022, a Grandoreiro variant was observed leveraging enhanced detection evasion techniques and had several new features: keylogging... In 2024, Casabaneiro (Mekotio) was observed targeting financial systems... displaying the capabilities to produce fake banking pop-ups to capture banking credentials, capture screenshots, log keystrokes, and access clipboard data.
the malware is capturing user input patterns, particularly mouse movements... “Record for 5 seconds the client’s average mouse speed”
Grandoreiro has capabilities to both steal data through keyloggers and screen-grabbers as well as steal bank login information from overlays when an infected victim visits pre-determined banking sites targeted by the threat actors.
In 2022, a Grandoreiro variant was observed leveraging enhanced detection evasion techniques and had several new features: keylogging, automatically applying updates to itself, web injection, command execution...
Operators behind Grandoreiro are equipped with a wide variety of remote commands, including an option to lock the user screen and present a custom image (overlay) to ask the victim for extra information.
These are some RAT features that we found in this version: ... Monitoring Outlook emails for specific keywords
The content repeatedly describes threat actors and malware using HTTP and HTTPS for command and control, such as: "Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests."
The loader will then download and run the final Grandoreiro payload and check in with a command and control (C2) server.
70 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
84 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as another Brazilian banking trojan grouped alongside Ousaban under the 'Tetrade' label.
Named as another Brazilian banking trojan used as comparison/background for the broader trend targeting Iberian markets.
Brazilian banking trojan cited as part of the same 'Tetrade' cluster and used as comparison for similar delivery tradecraft against Iberian banking targets.
Banking trojan targeting victims in Mexico with capabilities including keylogging, self-updating, web injection, command execution, desktop manipulation, malicious URL lures, simulated user input, and DGA-based C2 generation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.