Grandoreiro has resurfaced in a new campaign targeting Latin America, with Mexico accounting for about 40% of observed detections and additional activity seen in Spain, Peru, Argentina, plus smaller clusters in Europe and North America. Researchers said the banking trojan is being delivered through a DLL sideloading chain that abuses the legitimate Duplicate Files Finder application alongside a malicious mingwm10.dll, allowing the malware to launch while hiding the program interface to reduce user suspicion.
The malware uses a protected loader with extensive anti-analysis checks before reaching command-and-control infrastructure, including uptime validation, shortcut and process checks, VM artifact detection, geolocation filtering, and username or hostname screening. If a system passes those checks, Grandoreiro resolves its infrastructure through Google DNS-over-HTTPS and attempts to fetch a second-stage payload over TCP port 6432 using encrypted host-specific requests, underscoring how the operation has remained active and shifted toward stealthier, lower-volume tactics despite a major 2024 law-enforcement disruption.

Get the actors, campaigns, and ATT&CK mapping behind it.
6 events from the most recent confirmed update back to the earliest known activity.
Telemetry from the last 30 days of June showed Mexico as the largest source of detected Grandoreiro samples, accounting for 40% of observed detections. Additional detections were reported in Spain, Peru, and Argentina, with smaller clusters in Europe and North America.
The malicious mingwm10.dll used in the sideloading chain carried a PE compilation timestamp of 2026/05/01, indicating the malware component used in the campaign was built by that date.
In May 2026, Grandoreiro operators launched a renewed campaign abusing the legitimate Duplicate Files Finder application for DLL sideloading. The chain used a renamed executable with legitimate dependencies and a malicious mingwm10.dll to execute the malware.
A coordinated operation led by Brazil's Polícia Federal and coordinated through INTERPOL with Spanish authorities disrupted significant portions of Grandoreiro infrastructure. Later reporting said the action disrupted parts of the malware's infrastructure but did not eliminate the operation.
Grandoreiro, a Brazilian-origin Delphi banking trojan, had been operating across Latin America since at least 2016, historically targeting financial institutions and their customers through phishing and social engineering.
Acronis Threat Research Unit published research detailing that Grandoreiro checks for virtualization, sandbox artifacts, security tools, and system configuration details before contacting command-and-control infrastructure. The report added new technical insight into the malware's evasion behavior during the renewed 2026 campaign.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 26 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
5 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcedarkreading.com
Open sourcescworld.com
Open sourceinfosecurity-magazine.com
Open sourceacronis.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.