Last seven days
- First activity
- Aug 11, 2026
- Last activity
- Aug 11, 2026
- Feed role
- C2
- Host form
- 3 IP / 0 hostnames
Grandoreiro is a Delphi-based Brazilian banking trojan active since at least 2016 and widely associated with the Latin American banking malware cluster often referred to as the Tetrade.
Profile source: Mallory opens in a new tabGrandoreiro
Grandoreiro is a Delphi-based Brazilian banking trojan active since at least 2016 and widely associated with the Latin American banking malware cluster often referred to as the Tetrade. It is designed to facilitate fraudulent banking operations by abusing the victim’s own device and session, allowing operators to bypass institution-side security controls. Over time it expanded from Brazil and Mexico into Spain, Portugal, broader Europe, and other regions worldwide, with targeting reported against large numbers of banks and cryptocurrency wallet services across dozens of countries and territories.
Grandoreiro is primarily distributed through phishing campaigns, typically using tax, invoice, utility, document-sharing, or update-themed lures. Observed delivery chains include phishing emails containing links to ZIP archives, malicious attachments, MSI, HTA, EXE, and VBS-based loaders, as well as campaigns using malvertising. Multiple campaigns have used DLL sideloading with legitimate signed software to launch malicious Delphi DLL payloads. Operators have also used oversized padded binaries, CAPTCHA checks, geofencing, anti-debugging, virtualization checks, and security-product discovery to reduce analysis and detection.
Functionally, Grandoreiro is a full-featured banking trojan with remote-access capabilities. It can steal credentials through keylogging, screen capture, clipboard capture, and banking overlays shown when victims access targeted financial sites. It has been reported to support web injection, command execution, desktop window manipulation, simulated mouse or keyboard activity, self-updating, and operator-driven remote control of the victim machine during live banking sessions. Recent versions also include cryptocurrency-focused theft features such as clipboard replacement aimed at wallet redirection. The malware can enumerate installed security products and collect host profiling data including username, system configuration, language, time zone, browser and software presence, and geolocation.
Grandoreiro has been linked in reporting to threat clusters including TA2725 and to criminal operators targeted by international law-enforcement actions involving Brazil, Spain, Argentina, and INTERPOL. Those disruptions did not eliminate the threat, and subsequent reporting indicates continued development, fragmented code branches, evolving encryption, and dynamic command-and-control generation through DGA mechanisms. Grandoreiro remains one of the most significant banking malware families affecting Windows users, financial institutions, and banking customers in Latin America and Europe.
C2 tracking
Derp observations, rolling seven-day window
Samples
1debdf6c9ad90caca19643b53030e347cff8ac4e02cfbda8d39cc4d409bd83cc 3a2584e9d358beacb1c65df6697c26e08d3bbd40febb1f4d94e3bc615b55a126 6d459830f69a25b4647288e35eaad9d494ddca369ed776592c171c105bd17d4f 9cff99340825973883bfebb79264a463470d84d8e7fb13db85fa9b6808f2b98c c011a552081dead8ee59da97d6c7004c179a58fcfe2fdfa11967b6502bc295b9 fffa5be744fc2315cdec4636a6c098c31ca40794a902883362badf0ac3f0c5bd Reported operators
A new version of Grandoreiro malware from TA2725 targets both Mexico and Spain. Previously this malware has only targeted victims in Brazil and Mexico.
In 2025, Brazilian-origin families such as Grandoreiro (part of the Tetrade group) stood out for their constant activity and global reach. Despite a major law enforcement disruption in early 2024, Grandoreiro remained active in 2025, re-emerging with updated variants and continuing to operate.
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.