ESET reported that several major Latin American banking trojan families—including Amavaldo, Casbaneiro, Mispadu, Guildma, Grandoreiro, and Mekotio—are distinct malware operations that nonetheless share extensive code, delivery logic, and operational techniques. Researchers said the overlap spans uncommon libraries, obfuscation methods, domain generation algorithms, string-encryption routines, and near-identical banking-trojan behavior, indicating close cooperation among financially motivated threat actors rather than coincidence.
The campaigns commonly use spearphishing attachments and links to deliver payloads, often through ZIP archives, malicious documents, and MSI installers, with Visual Basic–based scripts and macros used for execution and staging. Once launched, the malware typically establishes persistence through Registry Run keys or Startup folders, uses DLL side-loading, and steals banking credentials through fake pop-up windows, keylogging, screenshots, and security-software discovery; ESET also noted that several of these families expanded beyond Latin America to target victims in Spain and Portugal.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
ESET published a white paper and accompanying analysis concluding that Latin American banking trojans are multiple distinct malware families that share code, delivery logic, and techniques extensively enough to indicate close cooperation among multiple threat actors.
ESET observed that since late 2019, several Latin American banking trojan families expanded beyond their usual Latin American targets to also target victims in Spain and Portugal.
ESET reported that since 2019, the vast majority of several Latin American banking trojan families have used Windows Installer MSI files as the first stage of their distribution chains.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
welivesecurity.com
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.