Frequency
6
occurrences
First Seen
July 1, 2026
Last Seen
September 1, 2026
Related Threat Clusters
-
Ousaban Banking Trojan Targets Users in Spain and Portugal with Advanced Techniques
The Ousaban banking trojan has been identified targeting Windows users in Spain and Portugal since May 2026. This malware employs phishing PDFs disguised as corrupted files to lure victims into clicking an 'Atualizar'…
8 articles · Updated July 1, 2026 -
Guildma (Astaroth) Malware Infection via Geofenced Brazilian Email
On August 31, 2026, a Windows host was infected with Guildma (Astaroth) malware through a malicious email targeting Brazilian users. The email contained a geofenced link that delivered a ZIP archive with a Windows…
2 articles · Updated September 1, 2026 -
Grandoreiro Banking Trojan Resurfaces in Mexico with DLL Sideloading Tactics
The Grandoreiro banking trojan has re-emerged in a new campaign targeting users in Mexico, which accounted for 40% of observed detections. This malware, originating from Brazil, employs DLL sideloading techniques using…
5 articles · Updated August 19, 2026
Recent Intelligence Reports
- Guildma (Astaroth) malware infection from Brazilian Portuguese email — Socprime · September 1, 2026
- Guildma (Astaroth) — malpedia.caad.fkie.fraunhofer.de · September 1, 2026
- Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st) — Isc.Sans.Edu · September 1, 2026
- Grandoreiro goes north: From Brazil to Mexico with a new DLL sideloading campaign — Acronis · August 19, 2026
- Ousaban banking trojan targets Spain and Portugal with new stealth techniques — Feeds.Feedburner · July 1, 2026
- A Brazilian banking trojan is targeting Santander and BBVA customers with fake PDF lures — Thenextweb · July 1, 2026