Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
credential-stealer-activityphishing-campaign-intelligenceloader-delivery-mechanismdefense-evasion-method

Grandoreiro Banking Trojan Expands Global Reach and Evasion Tactics

Updated 10d agoFirst seen Jan 1, 20241 source

Kaspersky reported that the Grandoreiro banking trojan has continued operating globally despite law-enforcement disruptions and arrests, expanding from targeting about 900 banks in 40 countries in 2023 to roughly 1,700 banks and 276 crypto wallets across 45 countries and territories in 2024. Telemetry recorded more than 150,000 blocked infection attempts affecting over 30,000 users worldwide between January and October 2024, underscoring the malware’s sustained scale and resilience.

Recent Grandoreiro campaigns used phishing emails, malvertising, MSI-based loaders, DLL sideloading, oversized padded binaries, and CAPTCHA-based sandbox evasion to infect victims. Kaspersky said newer versions also introduced fragmented codebases, stronger encryption, three domain generation algorithms for command-and-control, and mouse-behavior tracking to evade fraud detection, while preserving core capabilities including remote machine control, credential theft, one-time-password harvesting through overlays, clipboard replacement for cryptocurrency theft, and fraudulent banking transactions; some legacy variants are now concentrating on targets in Mexico.

Share:
Grandoreiro Banking Trojan Expands Global Reach and Evasion Tactics
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Jan 1, 20242y ago

Grandoreiro expands to 1,700 banks and 276 crypto wallets

In 2024, Kaspersky reports Grandoreiro expanded its targeting from 900 banks in 40 countries to 1,700 banks and 276 crypto wallets in 45 countries and territories. The malware also evolved with fragmented codebases, stronger encryption, DGAs, and anti-analysis features.

Grandoreiro banking trojan: overview of recent versions and new tricks | Securelist

Law enforcement disruptions and arrests hit Grandoreiro in 2024

The reference says Grandoreiro also faced law enforcement disruptions and arrests in 2024. Despite those actions, the malware operation continued globally.

Grandoreiro banking trojan: overview of recent versions and new tricks | Securelist
Jan 1, 20233y ago

Grandoreiro targets 900 banks in 40 countries in 2023

According to Kaspersky, Grandoreiro targeted 900 banks across 40 countries in 2023. This establishes the scale of the malware's operations before its later expansion in 2024.

Grandoreiro banking trojan: overview of recent versions and new tricks | Securelist
May 13, 20215y ago

Kaspersky records 150,000 blocked Grandoreiro infections

From January to October 2024, Kaspersky telemetry recorded more than 150,000 blocked Grandoreiro infections affecting over 30,000 users worldwide. This provides a measured view of the campaign's impact during that period.

Grandoreiro banking trojan: overview of recent versions and new tricks | Securelist
Jan 1, 20215y ago

Law enforcement disruptions and arrests hit Grandoreiro in 2021

The reference says Grandoreiro continued operating despite law enforcement disruptions and arrests in 2021. This indicates authorities took action against actors tied to the malware that year.

Grandoreiro banking trojan: overview of recent versions and new tricks | Securelist
Jan 1, 201610y ago

Grandoreiro banking trojan becomes active

Kaspersky states that the Grandoreiro banking trojan has been active since at least 2016. The malware is described as a Brazilian banking trojan that continued operating globally in subsequent years.

Grandoreiro banking trojan: overview of recent versions and new tricks | Securelist
SOURCE COVERAGE

Sources

1 reference tracked. Mallory keeps watching after this page renders.

1 SOURCESView all
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.