Grandoreiro

MITRE ATT&CK: S0531 View on attack.mitre.org

Aliases: Grandoreiro

First seen
2016-01-01 00:00:00
Malware type
trojan
Family
Malware family
Operating systems
windows
Related IoCs
415 (406 malicious)
Last IoC activity
2026-08-28 00:49:57
Profile updated
2026-07-07 13:12:58

Targeted industries: financial-services

Targeted regions: country_code:br country_code:mx country_code:pt country_code:es

Context

Grandoreiro is a banking trojan written in Delphi that was first observed in 2016 and uses a Malware-as-a-Service (MaaS) business model. Grandoreiro has confirmed victims in Brazil, Mexico, Portugal, and Spain.

Recent IoC activity

406 malicious indicators in Maltiverse are attributed to Grandoreiro (S0531). The 20 most recently updated:

TypeIndicatorUpdatedSources
file sample NmclFBSPK0822095_OFGVC.iso 2026-08-28 1
hostname 39eikc.rodrigomonteiro.one 2026-08-26 1
file sample c3464f9f53cfe11f662d90adee7c4af7.hta 2026-08-26 2
file sample 7e6d15d3044030f37a670ae6514ddbe0.hta 2026-08-26 1
file sample 44c0f9d642dc053e7f530330710f6ec6.hta 2026-08-26 1
file sample 68fa83073c621348a2ecc8c32e0ba8e6.hta 2026-08-26 2
file sample TMS3836I3C880124.iso 2026-08-24 1
hostname jghskd9kfx7.brazilsouth.cloudapp.azure.com 2026-08-19 1
hostname dkawt.joaomiguelcunha.one 2026-08-18 1
file sample TMS87997334Z08207.iso 2026-08-18 1
file sample 168511c2fd09e21c93ce1202902b66813385a4694503493ddb70ba13aea26c3b 2026-08-17 2
file sample Binary.adalats.dll 2026-08-16 1
file sample HbrO3D3B3830322_YQHGpgmpn-NotaP8LV.iso 2026-08-12 1
IP address 54.91.129.132 2026-08-11 1
hostname mapfre.homesecuritypc.com 2026-08-10 1
file sample 0Ofc9456PRGCLBJ6X6-91664.iso 2026-08-09 1
file sample IBER79986_2025-03-24-NU5B6626048_Z23N9.zip 2026-08-06 1
file sample SecuriteInfo.com.TScope.Trojan.Delf.7638.13014 2026-08-05 1
file sample [email protected] 2026-08-02 1
file sample fee0824bcc6bc86c65ecfb522035e66a86842956eab83153eda141c20709b5f8 2026-08-02 2

Detection coverage

  • 1 YARA rules
  • 685 Sigma rules

Malware & tools used

  • Visual Basic (attack-pattern)
  • Malicious Link (attack-pattern)
  • Process Discovery (attack-pattern)
  • Shortcut Modification (attack-pattern)
  • Steal Web Session Cookie (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Asymmetric Cryptography (attack-pattern)
  • Dead Drop Resolver (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Modify Registry (attack-pattern)
  • Bidirectional Communication (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Windows Permissions (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • System Time Discovery (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Malicious File (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Application Window Discovery (attack-pattern)
  • Fileless Storage (attack-pattern)
  • Email Account (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Binary Padding (attack-pattern)
  • Msiexec (attack-pattern)
  • Security Software Discovery (attack-pattern)

Detection rules

  • SEKOIA_Trojan_Win_Grandoreiro (yara-rule)

Reports & references

  • proofpoint.com — Copacabana Barcelona Cross Continental Threat Brazilian Banking Malware (report)
  • ESET — Eset Threat Report Q22020 (report)
  • Kaspersky — 97779 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Grandoreiro (report)
  • zscaler.com — Grandoreiro Banking Trojan New Ttps Targeting Various Industry Verticals (report)
  • bleepingcomputer.com — Police Disrupt Grandoreiro Banking Malware Operation Make Arrests (report)
  • metabaseq.com — Grandoreiro Banking Malware Deciphering The Dga (report)
  • interior.gob.es — 13552853 (report)
  • incibe.es — Incibe Cert Study Grandoreiro Analysis 2022 V1 (report)
  • seguranca-informatica.pt — The Updated Grandoreiro Malware Equipped With Latenbot C2 Features In Q2 2020 Now Extended To Portuguese Banks (report)
  • securityintelligence.com — Grandoreiro Banking Trojan Unleashed (report)
  • ESET — Grandoreiro How Engorged Can Exe Get (report)
  • blueliv.com — Minireport Blueliv Bancos Esp Lat (report)
  • socradar.io — Grandoreiro Malware Campaign A Global Threat To Banking Security (report)
  • trustwave.com — Grandoreiro Banking Malware Resurfaces For Tax Season (report)
  • Kaspersky — 114257 (report)
  • therecord.media — Spain Arrests 16 For Distributing The Mekotio And Grandoreiro Banking Trojans (report)
  • ESET — Eset Takes Part Global Operation Disrupt Grandoreiro Banking Trojan (report)
  • MITRE ATT&CK — S0531 (report)

External references