Brazilian Federal Police, supported by ESET, Interpol, Spain’s National Police, and Caixa Bank, disrupted the Grandoreiro banking trojan operation and arrested five suspects tied to its infrastructure. Investigators said the malware crew had been active since at least 2017, primarily targeting Spain, Mexico, Brazil, and Peru, and used the trojan to conduct hands-on banking fraud through credential phishing, remote interaction with victims’ machines, screen monitoring, and keylogging. Authorities said the group moved at least €3.6 million through fraud since 2019, while Caixa Bank linked the operators to roughly $120 million in losses.
Grandoreiro was distributed through spam campaigns using fake Java or Flash updates and other lures, including COVID-19-themed messages, with payloads often delivered in encrypted ZIP archives via public file-sharing services. ESET said the Delphi-based malware used a modular design with bank-specific DLLs, a domain generation algorithm (DGA) for command-and-control discovery, registry-stored configuration, startup-folder persistence, and evasion features such as binary padding and anti-emulation; it also stole credentials from Chrome and Outlook and attempted to disable banking protection tools. By tracking the DGA and clustering command-and-control servers, researchers estimated about 551 daily unique connections and 114 new daily victims, and said the law-enforcement action appears to have halted the operation for now, though a return on new infrastructure remains possible.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Brazilian Federal Police, supported by ESET, Interpol, Spain's National Police, and Caixa Bank, disrupted the Grandoreiro banking malware operation using partner-provided data to identify operators and infrastructure.
On January 30, Brazilian Federal Police launched Operation Grandoreiro, carried out 13 search-and-seizure actions across multiple states, and announced five arrests tied to the malware's infrastructure.
In August 2022, a Zscaler report described a Grandoreiro campaign aimed at high-value company employees in Spain and Mexico.
On April 28, 2020, ESET documented Grandoreiro's spam-based delivery, modular banking malware architecture, DGA-based command-and-control, persistence, and evasion techniques.
Brazilian police said the criminal structure behind Grandoreiro is suspected of moving at least €3.6 million through fraud since 2019.
Grandoreiro has been active since at least 2017, targeting victims in countries including Brazil, Mexico, Spain, and Peru through banking fraud campaigns.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcewelivesecurity.com
Open sourcewelivesecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.