Skip to content
'Grandoreiro' Malware Resurfaces With Mexico Campaign

'Grandoreiro' Malware Resurfaces With Mexico Campaign

Darkreading Jai Vijayan August 20, 2026

Breaking cybersecurity news, news analysis, commentary, and other content from around the world, with an initial focus on the Middle East & Africa, the Asia Pacific, Europe, and Latin America.

The banking Trojan, post-law enforcement takedown, is sprucing itself up with features that make detection and analysis harder.

The Grandoreiro banking Trojan continues to pose a significant threat to banking customers, primarily in Latin America, more than two years after law enforcement disrupted its operations.

The latest evidence is a new campaign using the 12-year-old payload that's targeting users in Mexico. The operators are using DLL sideloading and a legitimate file-management application to deliver the malware.

Telemetry from the campaign that security vendor Acronis analyzed showed a handful of victims in North America and Europe as well. But "the overall distribution continues to reflect the malware's long-standing focus on Spanish-speaking regions," Acronis said in a report this week.

More importantly, "this campaign highlights the continued evolution of Grandoreiro and its operators' focus on stealth and evasion," Acronis said.

Grandoreiro is a banking Trojan that first surfaced in 2016. Written in Delphi by likely Brazilian Portuguese-speaking malware developers, it initially targeted banking customers in Brazil but has since expanded to other Latin American countries and regions around the world .

In 2024, researchers at IBM — among several security firms tracking the malware — found Grandoreiro targeting customers of more than 1,500 banks in more than 60 countries across South and Central America, Europe, Africa and the Indo-Pacific region. IBM concluded that it was likely being operated as a malware-as-a-service (MaaS) operation, which could make it more difficult to eradicate completely.

Later that year, Kaspersky put the number of targeted banks at 1,700 across 45 countries, and estimated that Grandoreiro and its variants accounted for 5% of all banking-Trojan attacks in 2024. The malware is primarily used to steal banking credentials and other financial information, with capabilities including keystroke logging, screen sharing, and remote control of infected devices.

Grandoreiro is one of numerous banking Trojans that attackers have used over the years to steal credentials and other information for accessing online banking and financial accounts and to steal money from them. Other notable examples include Dridex , SharkBot, mobile banking Trojan Xenomorph, and Ursnif , one of several banking Trojans that attackers repurposed for other malicious activities. Law enforcement in Brazil and Spain, with the help of Interpol, disrupted Grandoreiro operations in 2024 and arrested five administrators behind it. Since then, its operations have scaled down considerably ... but clearly have not entirely stopped.

In the latest campaign, Grandoreiro's operators are using a zip archive disguised as an invoice to deliver the malware, most likely via spam email, according to Acronis. The archive contains what appear to be legitimate PDF and XML documents that serve as decoys, making the file appear benign to antivirus and other security tools. It also includes a copy of Duplicate Files Finder, a legitimate application for finding and removing redundant files, that the attackers have repurposed to load Grandoreiro.

The attack relies on DLL sideloading , a technique in which malware abuses a legitimate application to load a malicious dynamic link library . In this case, the attackers modified Duplicate Files Finder so that when it runs, it also loads malicious code that launches Grandoreiro. Acronis found that the malicious component first checks the victim's computer for security controls and signs that it might be running in a security sandbox. If the system passes those checks, the malware communicates with the attackers' command-and-control (C2) server and downloads the main Grandoreiro payload.

What makes the latest version of the loader notable, according to Acronis, is its extensive anti-analysis and anti-forensics features, all designed to prevent researchers and automated security systems from examining it. Before contacting its C2 infrastructure for instance, the loader checks system uptime and for the presence of a particular combination of applications, like Google Chrome, Firefox, CCleaner, and Firefox Edge, to make sure it is not running in a sandbox. It also checks available memory and processors, disk space, screen resolution, recent user activity, and for the presence of nearly 50 security, debugging, reverse-engineering, and network-monitoring tools.

Meanwhile, the decision by the operators to use a "heavily protected loader" to deliver Grandoreiro also suggests a new, deliberate focus on separating initial access from the malware's long-term capabilities. "While overall activity associated with Grandoreiro has decreased compared to its peak, the campaign shows that it remains active and continues to adapt its tooling and infrastructure."

Illinois-based Jai Vijayan is a veteran, award-winning technology journalist with more than 25 years of experience covering cybersecurity. His information security reporting has explored everything from ransomware, nation-state threats, and identity security to AI risk, critical infrastructure protection, software supply chain security, cloud security and emerging enterprise technologies.

Over the course of his career, Jai has written news stories, feature articles, survey reports, white papers, and e-books for enterprise and technology audiences. He has also moderated panel discussions and executive roundtables featuring CISOs, security researchers, and industry leaders.

Jai previously served as senior editor at Computerworld, where he covered information security and data-privacy issues. His work has also appeared in CSO Online, InformationWeek, The Christian Science Monitor Passcode, The Economic Times, and other publications.

His work has earned multiple industry honors, including a Joint ASBPE Excellence Award for Best Coverage of Government IT, and a Joint Jesse H. Neal Award for wireless LAN security coverage. Jai holds a Master’s degree in statistics from Bangalore University, and studied broadcasting and electronic communication at Marquette University in Milwaukee.

The State of Cloud Security: The Latest Challenges

How Organizations Are Managing Incident Response

How Enterprises Are Developing Secure Applications

Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy

Essential News & Insights from Black Hat USA 2025

What Every Enterprise Should Know Securing Cloud Assets In the Age of AI

The Dos and Don'ts of a Cybersecurity Awareness Month People Actually Remember

Building a Secure AI Strategy for the Enterprise

Is your AppSec program Mythos Ready?

Experts Explain How to Develop a Framework for Cyber-Fraud Fusion