Grandoreiro is a Delphi-based Windows banking trojan of Brazilian origin that has targeted financial institutions and banking customers in Latin America since at least 2016, later expanding activity into Europe and North America. It is primarily used to steal banking credentials and financial information, including credentials and cookie data stored by Google Chrome. Documented capabilities include keystroke logging, screen sharing, remote control of compromised devices, host and account discovery, security-product identification, command-and-control data transmission, and persistence through Windows Run keys and Startup-folder shortcuts. Grandoreiro has historically been distributed through phishing and social-engineering campaigns, including malicious attachments. Recent activity has used invoice-themed archive lures and DLL sideloading through a renamed legitimate application to launch a protected loader and retrieve a subsequent payload. The loader employs extensive defense evasion, including sandbox and virtual-machine detection, process blacklisting, environment profiling, geolocation filtering, encrypted strings, and delayed execution. A coordinated Brazilian, Spanish, and INTERPOL-supported law-enforcement operation disrupted significant infrastructure in 2024, but Grandoreiro remained active at lower volume. Campaigns observed in 2026 were concentrated in Latin America, particularly Mexico.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A new version of Grandoreiro malware from TA2725 targets both Mexico and Spain. Previously this malware has only targeted victims in Brazil and Mexico.
In 2025, Brazilian-origin families such as Grandoreiro (part of the Tetrade group) stood out for their constant activity and global reach. Despite a major law enforcement disruption in early 2024, Grandoreiro remained active in 2025, re-emerging with updated variants and continuing to operate.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
The content is a MITRE ATT&CK-style listing of many malware families and threat groups using Windows/native OS APIs for execution, injection, discovery, anti-debugging, and other actions, ending with 'NtCreateProcess' and 'fork()'.
The malware used encrypted strings to complicate analysis
This allows the malware to blend with regular software activity and avoid detection.
Attackers take the legitimate Duplicate Files Finder application and rename it to a random filename.
Grandoreiro implements a custom string obfuscation scheme that combines a proprietary decryption routine with Base64 encoding to encode runtime strings and complicate static analysis.
It measures system uptime... counts processors, checks memory and free disk space, and reads the screen resolution. Moreover, it scans for VMware and VirtualBox drivers and registry artifacts.
The malware employs extensive anti-analysis checks, looking for virtualization, sandbox artifacts, security tools, and specific system configurations before contacting its command-and-control (C2) infrastructure.
The malware is primarily used to steal banking credentials and other financial information, with capabilities including keystroke logging, screen sharing, and remote control of infected devices.
Agent Tesla can gather credentials from a number of browsers... APT33 has used a variety of publicly available tools like LaZagne to gather credentials... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge... SELECT action_url, username_value, password_value FROM logins; CryptUnprotectData
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
Next, the malware contacts ip-api.com to determine the victim's public IP address and geolocation.
The content repeatedly describes malware and threat actors collecting the victim username, identifying logged-in users, running whoami, query user, quser, or similar commands to determine the current user or user sessions.
The malware also inspects running processes. In total, it looks for 49 tools tied to debugging, reverse engineering and network analysis.
It measures system uptime... counts processors, checks memory and free disk space, and reads the screen resolution... That request carries host details, such as the username, hostname and antivirus name.
It measures system uptime... counts processors, checks memory and free disk space, and reads the screen resolution. Moreover, it scans for VMware and VirtualBox drivers and registry artifacts.
Static analysis revealed that the malware issues an HTTP GET request over TCP port 6432 to retrieve the second-stage payload.
To hide the lookup, it resolves its hardcoded domain through Google’s DNS-over-HTTPS service.
Next, it sends an encrypted request to fetch a second-stage payload.
208 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
130 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Grandoreiro is a banking trojan active since at least 2016 that targets bank users. In this campaign it is delivered with suspected invoice-themed spam ZIP archives, uses DLL sideloading via a renamed legitimate application, checks for analysis environments and security tools, and—after passing those checks—uses Google's DNS-over-HTTPS resolver to contact C2 and request an encrypted second-stage payload while sending host profiling data.
Grandoreiro is identified as a banking trojan whose activity has reactivated in Latin America.
Banking trojan identified as active in Mexico.
Long-running Windows banking trojan of Brazilian origin targeting users in Latin America, Europe, and North America. Recent samples abuse the legitimate Duplicate Files Finder application for DLL sideloading and include extensive anti-analysis and sandbox-evasion checks before contacting C2 infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.