Grandoreiro
MITRE ATT&CK: S0531 View on attack.mitre.org
Aliases: Grandoreiro
- First seen
- 2016-01-01 00:00:00
- Malware type
- trojan
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 415 (406 malicious)
- Last IoC activity
- 2026-08-28 00:49:57
- Profile updated
- 2026-07-07 13:12:58
Targeted industries: financial-services
Targeted regions: country_code:br country_code:mx country_code:pt country_code:es
Context
Grandoreiro is a banking trojan written in Delphi that was first observed in 2016 and uses a Malware-as-a-Service (MaaS) business model. Grandoreiro has confirmed victims in Brazil, Mexico, Portugal, and Spain.
Recent IoC activity
406 malicious indicators in Maltiverse are attributed to Grandoreiro (S0531). The 20 most recently updated:
Detection coverage
- 1 YARA rules
- 685 Sigma rules
Malware & tools used
- Visual Basic (attack-pattern)
- Malicious Link (attack-pattern)
- Process Discovery (attack-pattern)
- Shortcut Modification (attack-pattern)
- Steal Web Session Cookie (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Asymmetric Cryptography (attack-pattern)
- Dead Drop Resolver (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Modify Registry (attack-pattern)
- Bidirectional Communication (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Windows Permissions (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- System Time Discovery (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Malicious File (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Application Window Discovery (attack-pattern)
- Fileless Storage (attack-pattern)
- Email Account (attack-pattern)
- System Information Discovery (attack-pattern)
- Binary Padding (attack-pattern)
- Msiexec (attack-pattern)
- Security Software Discovery (attack-pattern)
Detection rules
- SEKOIA_Trojan_Win_Grandoreiro (yara-rule)
Reports & references
- proofpoint.com — Copacabana Barcelona Cross Continental Threat Brazilian Banking Malware (report)
- ESET — Eset Threat Report Q22020 (report)
- Kaspersky — 97779 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Grandoreiro (report)
- zscaler.com — Grandoreiro Banking Trojan New Ttps Targeting Various Industry Verticals (report)
- bleepingcomputer.com — Police Disrupt Grandoreiro Banking Malware Operation Make Arrests (report)
- metabaseq.com — Grandoreiro Banking Malware Deciphering The Dga (report)
- interior.gob.es — 13552853 (report)
- incibe.es — Incibe Cert Study Grandoreiro Analysis 2022 V1 (report)
- seguranca-informatica.pt — The Updated Grandoreiro Malware Equipped With Latenbot C2 Features In Q2 2020 Now Extended To Portuguese Banks (report)
- securityintelligence.com — Grandoreiro Banking Trojan Unleashed (report)
- ESET — Grandoreiro How Engorged Can Exe Get (report)
- blueliv.com — Minireport Blueliv Bancos Esp Lat (report)
- socradar.io — Grandoreiro Malware Campaign A Global Threat To Banking Security (report)
- trustwave.com — Grandoreiro Banking Malware Resurfaces For Tax Season (report)
- Kaspersky — 114257 (report)
- therecord.media — Spain Arrests 16 For Distributing The Mekotio And Grandoreiro Banking Trojans (report)
- ESET — Eset Takes Part Global Operation Disrupt Grandoreiro Banking Trojan (report)
- MITRE ATT&CK — S0531 (report)