Spanish authorities arrested 16 people in Operation Aguas Vivas for allegedly laundering funds stolen through the Mekotio and Grandoreiro banking trojans, seizing devices and dismantling a four-tier criminal structure used to receive fraudulent transfers, redistribute money, move funds abroad, and conceal account activity. Investigators said the group obtained more than €276,470 from compromised accounts and had access to roughly €3.5 million more that had not yet been transferred, underscoring how Brazilian banking malware operations had established a significant foothold in Spain.
Security researchers reported that the malware activity continued and evolved despite the arrests, with Mekotio returning in phishing campaigns that used Spanish-language lures, ZIP archives, obfuscated batch files, fileless PowerShell, and AutoHotkey or AutoIt-based execution to evade detection and launch the final payload. ESET and Check Point said Latin American banking trojans remain heavily spam-driven, rely on victims interacting with fake banking overlays to steal credentials, and are expanding beyond Brazil into Spain, Mexico, Portugal, Peru, and other parts of Europe, with Grandoreiro, Mekotio, and related families such as Casbaneiro showing continued operational growth rather than major changes to core fraud techniques.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
16 events from the most recent confirmed update back to the earliest known activity.
ESET published an overview of Latin American banking trojans, stating that at least eight families remained active and that the threat continued evolving across Brazil, Spain, and Mexico. The report also profiled dormant families and emphasized the manual, operator-driven nature of these fraud operations.
ESET reported that Grandoreiro ran its largest campaign so far in August and September 2021, targeting Spain. The malware family remained dominant in Spain during this period.
Check Point said the renewed Mekotio campaign began after the Spanish Civil Guard announced the arrest of 16 people involved with Mekotio distribution in July 2021. The announcement was treated as a disruption to local distribution gangs rather than the core operators.
ESET assessed that the June 2021 Spanish arrests affected Mekotio more heavily than Grandoreiro, and that Mekotio activity went quiet for almost two months afterward. The lull was temporary, as new distribution campaigns were later observed.
In June 2021, Spain's Guardia Civil arrested 16 suspects across multiple cities in Operation Aguas Vivas for laundering funds stolen through Mekotio and Grandoreiro infections. Authorities searched homes, seized devices, and said the group had received more than €276,470 while having access to about €3.5 million more.
ESET said Grandoreiro, Ousaban, and Casbaneiro greatly increased their reach in Q3 and Q4 2021 compared with earlier activity. Ousaban and Casbaneiro were described as dominating Brazil in the latest months covered by the report.
ESET stated that the Amavaldo banking trojan family became dormant around November 2020. This marked a decline of one previously active Latin American banking trojan family.
ESET published a detailed analysis of Mekotio covering its distribution chains, AutoIt-based execution, persistence, backdoor features, and command-and-control methods. The report also noted 38 different Mekotio distribution chains observed since 2018.
ESET reported that Zumanek was active exclusively in Brazil until the middle of 2020. It was identified as the first Latin American banking trojan family discovered by ESET.
ESET reported that Grandoreiro and Mekotio expanded from Latin America into Europe starting in 2020, mainly targeting Spain. The Record also cited this expansion as part of the backdrop to later Spanish arrests.
ESET said Lokorrito was active mainly in Mexico until the beginning of 2020, with additional builds targeting Brazil, Chile, and Colombia. The family was later categorized among dormant Latin American banking trojans.
ESET said its multi-part research series on Latin American banking trojans began in August 2019. That series later formed the basis for its broader overview of the malware ecosystem.
ESET reported that the Krachulka banking trojan family was active in Brazil until the middle of 2019. The family was later described as dormant.
The Record cited reporting that the Grandoreiro banking trojan family has existed since 2016. It was described as one of the Brazilian banking trojans later expanded into Europe.
ESET reported that the Mekotio Latin American banking trojan has been active since at least 2015. The malware primarily targeted victims in Brazil, Chile, Mexico, Spain, Peru, and Portugal.
Check Point Research reported a renewed Mekotio campaign using a revised infection chain with obfuscated batch files, fileless PowerShell, geography checks, and AutoHotkey execution of the final DLL. Researchers detected more than 100 attacks in recent weeks and linked the resurgence to adaptation after the Spanish arrests.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
welivesecurity.com
Open sourceresearch.checkpoint.com
Open sourcetherecord.media
Open sourcewelivesecurity.com
Open sourcesecurelist.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.