Skip to content

Grandoreiro

Grandoreiro is a Delphi-based Brazilian banking trojan active since at least 2016 and widely associated with the Latin American banking malware cluster often referred to as the Tetrade.

Profile source: Mallory opens in a new tab

Grandoreiro

Family profile

Grandoreiro is a Delphi-based Brazilian banking trojan active since at least 2016 and widely associated with the Latin American banking malware cluster often referred to as the Tetrade. It is designed to facilitate fraudulent banking operations by abusing the victim’s own device and session, allowing operators to bypass institution-side security controls. Over time it expanded from Brazil and Mexico into Spain, Portugal, broader Europe, and other regions worldwide, with targeting reported against large numbers of banks and cryptocurrency wallet services across dozens of countries and territories.

Grandoreiro is primarily distributed through phishing campaigns, typically using tax, invoice, utility, document-sharing, or update-themed lures. Observed delivery chains include phishing emails containing links to ZIP archives, malicious attachments, MSI, HTA, EXE, and VBS-based loaders, as well as campaigns using malvertising. Multiple campaigns have used DLL sideloading with legitimate signed software to launch malicious Delphi DLL payloads. Operators have also used oversized padded binaries, CAPTCHA checks, geofencing, anti-debugging, virtualization checks, and security-product discovery to reduce analysis and detection.

Functionally, Grandoreiro is a full-featured banking trojan with remote-access capabilities. It can steal credentials through keylogging, screen capture, clipboard capture, and banking overlays shown when victims access targeted financial sites. It has been reported to support web injection, command execution, desktop window manipulation, simulated mouse or keyboard activity, self-updating, and operator-driven remote control of the victim machine during live banking sessions. Recent versions also include cryptocurrency-focused theft features such as clipboard replacement aimed at wallet redirection. The malware can enumerate installed security products and collect host profiling data including username, system configuration, language, time zone, browser and software presence, and geolocation.

Grandoreiro has been linked in reporting to threat clusters including TA2725 and to criminal operators targeted by international law-enforcement actions involving Brazil, Spain, Argentina, and INTERPOL. Those disruptions did not eliminate the threat, and subsequent reporting indicates continued development, fragmented code branches, evolving encryption, and dynamic command-and-control generation through DGA mechanisms. Grandoreiro remains one of the most significant banking malware families affecting Windows users, financial institutions, and banking customers in Latin America and Europe.

Capabilities

  • Credential Theft
  • Crypto Theft
  • Defense Evasion
  • Dll Sideloading
  • Keylogging
  • Persistence
  • Post Exploitation
  • Reconnaissance
  • Session Hijacking
  • Spoofing

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 11, 2026
Last activity
Aug 11, 2026
Feed role
C2
Host form
3 IP / 0 hostnames

Leading locations

  • US3

Leading providers

  • Amazon.com, Inc.3

Infrastructure traits

  • Hosting 3

Samples

Recent associated samples

Reported operators

Threat actors

2 named in public reporting
TA2725

A new version of Grandoreiro malware from TA2725 targets both Mexico and Spain. Previously this malware has only targeted victims in Brazil and Mexico.

Tetrade

In 2025, Brazilian-origin families such as Grandoreiro (part of the Tetrade group) stood out for their constant activity and global reach. Despite a major law enforcement disruption in early 2024, Grandoreiro remained active in 2025, re-emerging with updated variants and continuing to operate.

MITRE ATT&CK

Grandoreiro in ATT&CK

80 distinct techniques

Techniques

80 techniques
T1565 Data Manipulation T1518.001 Security Software Discovery T1082 System Information Discovery T1547.001 Registry Run Keys / Startup Folder T1112 Modify Registry T1027 Obfuscated Files or Information T1566 Phishing T1059.007 JavaScript T1059 Command and Scripting Interpreter T1056.004 Credential API Hooking T1497 Virtualization/Sandbox Evasion T1036 Masquerading T1056.001 Keylogging T1560 Archive Collected Data T1566.002 Spearphishing Link T1568.002 Domain Generation Algorithms T1204 User Execution T1204.002 Malicious File T1033 System Owner/User Discovery T1140 Deobfuscate/Decode Files or Information T1016 System Network Configuration Discovery T1115 Clipboard Data T1071.001 Web Protocols T1614 System Location Discovery T1027.001 Binary Padding T1113 Screen Capture T1057 Process Discovery T1056 Input Capture T1056.002 GUI Input Capture T1218 System Binary Proxy Execution T1614.001 System Language Discovery T1568 Dynamic Resolution T1114 Email Collection T1566.001 Spearphishing Attachment T1056.003 Web Portal Capture T1518 Software Discovery T1622 Debugger Evasion T1105 Ingress Tool Transfer T1583 Acquire Infrastructure T1497.001 System Checks T1055.001 Dynamic-link Library Injection T1219 Remote Access Tools T1071 Application Layer Protocol T1059.005 Visual Basic T1555 Credentials from Password Stores T1012 Query Registry T1005 Data from Local System T1047 Windows Management Instrumentation T1555.003 Credentials from Web Browsers T1185 Browser Session Hijacking T1090 Proxy T1573 Encrypted Channel T1102 Web Service T1041 Exfiltration Over C2 Channel T1539 Steal Web Session Cookie T1553.002 Code Signing T1010 Application Window Discovery T1070.004 File Deletion T1562 Impair Defenses T1562.001 Disable or Modify Tools T1059.003 Windows Command Shell T1548.002 Bypass User Account Control T1059.001 PowerShell T1189 Drive-by Compromise T1124 System Time Discovery T1106 Native API T1027.011 Fileless Storage T1218.007 Msiexec T1573.002 Asymmetric Cryptography T1176.001 Browser Extensions T1027.013 Encrypted/Encoded File T1036.005 Match Legitimate Resource Name or Location T1102.001 Dead Drop Resolver T1547.009 Shortcut Modification T1087.003 Email Account T1562.013 Disable or Modify Network Device Firewall T1222.001 Windows File and Directory Permissions Modification T1204.001 Malicious Link T1102.002 Bidirectional Communication T1562.004 Disable or Modify System Firewall

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.