A new version of Grandoreiro malware from TA2725 targets both Mexico and Spain. Previously this malware has only targeted victims in Brazil and Mexico.
Grandoreiro
Grandoreiro is a Delphi-based Windows banking trojan of Brazilian origin that has targeted financial institutions and banking customers in Latin America since at least 2016, later expanding activity into Europe and North America.
Profile source: Mallory opens in a new tabGrandoreiro
Family profile
Grandoreiro is a Delphi-based Windows banking trojan of Brazilian origin that has targeted financial institutions and banking customers in Latin America since at least 2016, later expanding activity into Europe and North America. It is primarily used to steal banking credentials and financial information, including credentials and cookie data stored by Google Chrome. Documented capabilities include keystroke logging, screen sharing, remote control of compromised devices, host and account discovery, security-product identification, command-and-control data transmission, and persistence through Windows Run keys and Startup-folder shortcuts. Grandoreiro has historically been distributed through phishing and social-engineering campaigns, including malicious attachments. Recent activity has used invoice-themed archive lures and DLL sideloading through a renamed legitimate application to launch a protected loader and retrieve a subsequent payload. The loader employs extensive defense evasion, including sandbox and virtual-machine detection, process blacklisting, environment profiling, geolocation filtering, encrypted strings, and delayed execution. A coordinated Brazilian, Spanish, and INTERPOL-supported law-enforcement operation disrupted significant infrastructure in 2024, but Grandoreiro remained active at lower volume. Campaigns observed in 2026 were concentrated in Latin America, particularly Mexico.
Capabilities
- Credential Theft
- Defense Evasion
- Dll Sideloading
- Exfiltration
- Keylogging
- Persistence
- Post Exploitation
- Reconnaissance
- Session Hijacking
Reported operators
Threat actors
2 named in public reportingIn 2025, Brazilian-origin families such as Grandoreiro (part of the Tetrade group) stood out for their constant activity and global reach. Despite a major law enforcement disruption in early 2024, Grandoreiro remained active in 2025, re-emerging with updated variants and continuing to operate.
MITRE ATT&CK
Grandoreiro in ATT&CK
100 distinct techniquesTechniques
100 techniquesReporting
Research mentioning Grandoreiro
Armored Likho expands its cyber-espionage toolkit - Malware News - Malware Analysis, News and Indicators
Armored Likho, also tracked as Eagle Werewolf, launched a cyber-espionage campaign against private users and organizations in Russia, including targets in government, corporate, IT, and education sectors. The operation used fake charity-assistance applications built as Rust/Tauri droppers to install a new modular espionage framework called Still Toolkit. Its Still Sync component steals Telegram Desktop session data, authenticates to victims’ Telegram accounts, and exfiltrates chats, media, and account details through the Telegram API, while Still Audio covertly activates microphone surveillance by detecting speech and uploading recordings to command-and-control servers.
Новые инструменты Armored Likho нацелены на Telegram и прослушку | Securelist
New Armored Likho tools target Telegram and eavesdropping | Securelist
Detection: Windows Suspicious Child Process of Consent.EXE | Splunk Security Content
Splunk published a Windows endpoint analytic that detects suspicious child processes launched by consent.exe, a behavior strongly associated with User Account Control (UAC) bypass and privilege escalation. Because consent.exe normally displays the UAC elevation prompt rather than spawning executables, the detection treats such process creation as anomalous, excluding WerFault.exe as a known crash-related exception. The analytic maps to MITRE ATT&CK techniques T1548.002, T1068, and T1059, and is designed for telemetry from Sysmon, Windows Security Event ID 4688, and CrowdStrike ProcessRollup2 data normalized into Splunk's Endpoint data model. The release aligns with MITRE ATT&CK documentation showing UAC bypass remains a widely used post-compromise technique across ransomware operators, commodity malware, and state-linked intrusion groups. ATT&CK lists methods including COM abuse through CMSTPLUA, scheduled task abuse such as SilentCleanup, registry hijacks involving ms-settings and mscfile, and abuse of trusted Windows binaries including fodhelper.exe, eventvwr.exe, and sdclt.exe. Splunk also published supporting attack simulation data for suspicious child processes of consent.exe, giving defenders a way to test visibility for this privilege-escalation pattern, although the analytic is disabled by default and generates intermediate risk events rather than direct notable alerts.
Windows Suspicious Child Of Consent.exe | Splunk Security Content
Unholy trinity: werewolves target law enforces | Learn more
Триединое зло: "оборотни" атакуют сотрудников силовых структур - читайте на BI.ZONE
Lampion Trojan Utilizes New Delivery through Cloud-Based Sharing
Researchers reported renewed activity from the Lampion banking trojan, a malware family that has targeted Portuguese internet users since 2019 through phishing messages impersonating tax and banking institutions. The latest observed variant, release 212, preserves Lampion’s established credential-theft workflow while introducing a more heavily obfuscated VBS loader padded with junk code and unusually large files to reduce antivirus detection. The infection chain uses an initial script to generate additional VBS files, establish persistence through a scheduled task and startup-folder artifacts, and retrieve two DLL stages from AWS S3 buckets. The first DLL functions as a loader that extracts a password-protected second DLL containing the core Lampion payload, which retains export structures and decryption logic seen in earlier versions. Once active, the malware monitors running processes and browser page titles for hardcoded Portuguese and Brazilian banking targets, then displays overlay windows to steal credentials. Investigators also found that the campaign continued using the same command-and-control server, 5.188.9.28, reportedly geolocated in Russia, linking the operation to infrastructure observed in campaigns dating back to 2020.