Skip to content

Grandoreiro

Grandoreiro is a Delphi-based Windows banking trojan of Brazilian origin that has targeted financial institutions and banking customers in Latin America since at least 2016, later expanding activity into Europe and North America.

Profile source: Mallory opens in a new tab

Grandoreiro

Family profile

Grandoreiro is a Delphi-based Windows banking trojan of Brazilian origin that has targeted financial institutions and banking customers in Latin America since at least 2016, later expanding activity into Europe and North America. It is primarily used to steal banking credentials and financial information, including credentials and cookie data stored by Google Chrome. Documented capabilities include keystroke logging, screen sharing, remote control of compromised devices, host and account discovery, security-product identification, command-and-control data transmission, and persistence through Windows Run keys and Startup-folder shortcuts. Grandoreiro has historically been distributed through phishing and social-engineering campaigns, including malicious attachments. Recent activity has used invoice-themed archive lures and DLL sideloading through a renamed legitimate application to launch a protected loader and retrieve a subsequent payload. The loader employs extensive defense evasion, including sandbox and virtual-machine detection, process blacklisting, environment profiling, geolocation filtering, encrypted strings, and delayed execution. A coordinated Brazilian, Spanish, and INTERPOL-supported law-enforcement operation disrupted significant infrastructure in 2024, but Grandoreiro remained active at lower volume. Campaigns observed in 2026 were concentrated in Latin America, particularly Mexico.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Dll Sideloading
  • Exfiltration
  • Keylogging
  • Persistence
  • Post Exploitation
  • Reconnaissance
  • Session Hijacking

Reported operators

Threat actors

2 named in public reporting
TA2725

A new version of Grandoreiro malware from TA2725 targets both Mexico and Spain. Previously this malware has only targeted victims in Brazil and Mexico.

Tetrade

In 2025, Brazilian-origin families such as Grandoreiro (part of the Tetrade group) stood out for their constant activity and global reach. Despite a major law enforcement disruption in early 2024, Grandoreiro remained active in 2025, re-emerging with updated variants and continuing to operate.

MITRE ATT&CK

Grandoreiro in ATT&CK

100 distinct techniques

Techniques

100 techniques
T1082 System Information Discovery T1057 Process Discovery T1036.005 Match Legitimate Resource Name or Location T1566.001 Spearphishing Attachment T1564.001 Hidden Files and Directories T1497 Virtualization/Sandbox Evasion T1564.003 Hidden Window T1071.004 DNS T1573 Encrypted Channel T1105 Ingress Tool Transfer T1036 Masquerading T1497.001 System Checks T1219 Remote Access Tools T1056.001 Keylogging T1566 Phishing T1574.001 DLL T1614 System Location Discovery T1027 Obfuscated Files or Information T1140 Deobfuscate/Decode Files or Information T1016 System Network Configuration Discovery T1071.001 Web Protocols T1204.002 Malicious File T1555.003 Credentials from Web Browsers T1112 Modify Registry T1106 Native API T1555 Credentials from Password Stores T1033 System Owner/User Discovery T1539 Steal Web Session Cookie T1518.001 Security Software Discovery T1547.001 Registry Run Keys / Startup Folder T1204 User Execution T1547.009 Shortcut Modification T1176 Software Extensions T1041 Exfiltration Over C2 Channel T1070.004 File Deletion T1124 System Time Discovery T1547 Boot or Logon Autostart Execution T1189 Drive-by Compromise T1548.002 Bypass User Account Control T1059.005 Visual Basic T1071 Application Layer Protocol T1010 Application Window Discovery T1587.001 Malware T1573.001 Symmetric Cryptography T1056.002 GUI Input Capture T1529 System Shutdown/Reboot T1218.007 Msiexec T1114.001 Local Email Collection T1132.002 Non-Standard Encoding T1568.002 Domain Generation Algorithms T1571 Non-Standard Port T1027.001 Binary Padding T1056 Input Capture T1185 Browser Session Hijacking T1622 Debugger Evasion T1114 Email Collection T1566.002 Spearphishing Link T1537 Transfer Data to Cloud Account T1564 Hide Artifacts T1518 Software Discovery T1078 Valid Accounts T1568 Dynamic Resolution T1059.003 Windows Command Shell T1056.004 Credential API Hooking T1083 File and Directory Discovery T1113 Screen Capture T1048 Exfiltration Over Alternative Protocol T1560 Archive Collected Data T1012 Query Registry T1552.001 Credentials In Files T1059.007 JavaScript T1566.003 Spearphishing via Service T1132.001 Standard Encoding T1565 Data Manipulation T1059 Command and Scripting Interpreter T1115 Clipboard Data T1218 System Binary Proxy Execution T1614.001 System Language Discovery T1056.003 Web Portal Capture T1583 Acquire Infrastructure T1055.001 Dynamic-link Library Injection T1005 Data from Local System T1047 Windows Management Instrumentation T1090 Proxy T1102 Web Service T1553.002 Code Signing T1562 Impair Defenses T1562.001 Disable or Modify Tools T1059.001 PowerShell T1027.011 Fileless Storage T1573.002 Asymmetric Cryptography T1176.001 Browser Extensions T1027.013 Encrypted/Encoded File T1102.001 Dead Drop Resolver T1087.003 Email Account T1562.013 Disable or Modify Network Device Firewall T1222.001 Windows File and Directory Permissions Modification T1204.001 Malicious Link T1102.002 Bidirectional Communication T1562.004 Disable or Modify System Firewall

Reporting

Research mentioning Grandoreiro

Aug 13
Malware News

Armored Likho expands its cyber-espionage toolkit - Malware News - Malware Analysis, News and Indicators

Armored Likho, also tracked as Eagle Werewolf, launched a cyber-espionage campaign against private users and organizations in Russia, including targets in government, corporate, IT, and education sectors. The operation used fake charity-assistance applications built as Rust/Tauri droppers to install a new modular espionage framework called Still Toolkit. Its Still Sync component steals Telegram Desktop session data, authenticates to victims’ Telegram accounts, and exfiltrates chats, media, and account details through the Telegram API, while Still Audio covertly activates microphone surveillance by detecting speech and uploading recordings to command-and-control servers.

Aug 13
Securelist Ru

Новые инструменты Armored Likho нацелены на Telegram и прослушку | Securelist

Aug 13
Securelist

New Armored Likho tools target Telegram and eavesdropping | Securelist

Jul 30
Splunk Research

Detection: Windows Suspicious Child Process of Consent.EXE | Splunk Security Content

Splunk published a Windows endpoint analytic that detects suspicious child processes launched by consent.exe, a behavior strongly associated with User Account Control (UAC) bypass and privilege escalation. Because consent.exe normally displays the UAC elevation prompt rather than spawning executables, the detection treats such process creation as anomalous, excluding WerFault.exe as a known crash-related exception. The analytic maps to MITRE ATT&CK techniques T1548.002, T1068, and T1059, and is designed for telemetry from Sysmon, Windows Security Event ID 4688, and CrowdStrike ProcessRollup2 data normalized into Splunk's Endpoint data model. The release aligns with MITRE ATT&CK documentation showing UAC bypass remains a widely used post-compromise technique across ransomware operators, commodity malware, and state-linked intrusion groups. ATT&CK lists methods including COM abuse through CMSTPLUA, scheduled task abuse such as SilentCleanup, registry hijacks involving ms-settings and mscfile, and abuse of trusted Windows binaries including fodhelper.exe, eventvwr.exe, and sdclt.exe. Splunk also published supporting attack simulation data for suspicious child processes of consent.exe, giving defenders a way to test visibility for this privilege-escalation pattern, although the analytic is disabled by default and generates intermediate risk events rather than direct notable alerts.

Jul 22
Splunk Research

Windows Suspicious Child Of Consent.exe | Splunk Security Content

Apr 16
Bi Zone

Unholy trinity: werewolves target law enforces | Learn more

Feb 16
Bi Zone

Триединое зло: "оборотни" атакуют сотрудников силовых структур - читайте на BI.ZONE

Jan 1
Cofense

Lampion Trojan Utilizes New Delivery through Cloud-Based Sharing

Researchers reported renewed activity from the Lampion banking trojan, a malware family that has targeted Portuguese internet users since 2019 through phishing messages impersonating tax and banking institutions. The latest observed variant, release 212, preserves Lampion’s established credential-theft workflow while introducing a more heavily obfuscated VBS loader padded with junk code and unusually large files to reduce antivirus detection. The infection chain uses an initial script to generate additional VBS files, establish persistence through a scheduled task and startup-folder artifacts, and retrieve two DLL stages from AWS S3 buckets. The first DLL functions as a loader that extracts a password-protected second DLL containing the core Lampion payload, which retains export structures and decryption logic seen in earlier versions. Once active, the malware monitors running processes and browser page titles for hardcoded Portuguese and Brazilian banking targets, then displays overlay windows to steal credentials. Investigators also found that the campaign continued using the same command-and-control server, 5.188.9.28, reportedly geolocated in Russia, linking the operation to infrastructure observed in campaigns dating back to 2020.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.