Tetrade is an umbrella designation for a cluster of Brazilian banking-malware operations associated with Latin American financial cybercrime. The grouping is best known for banking trojan families such as Guildma, Grandoreiro, and Bizarro, and has also been linked to mobile banking malware activity through Guildma-associated tooling. These operations primarily target banks, payment services, fintech platforms, and cryptocurrency services, and are characterized by direct fraud enablement rather than broad destructive activity. Tetrade-linked malware commonly relies on phishing and spam-driven initial access, malicious installers, staged payload delivery, and social-engineering lures tailored to the victim’s language and banking context. Across the associated families, operators have used MSI-based loaders, ZIP-delivered payloads, compromised websites, malvertising, and DLL sideloading with legitimate signed binaries. Defense evasion is a recurring feature, including heavy obfuscation, anti-debugging, anti-emulation, sandbox checks, oversized padded binaries, CAPTCHA-based evasion, encrypted configuration data, and dynamic command-and-control resolution techniques including DGA-like methods. The group’s tooling is centered on credential theft and fraudulent transaction execution. Guildma-linked Android malware abuses Accessibility services for persistence and remote control, can interfere with device shutdown or uninstallation, hide its icon, and manipulate on-screen content to facilitate banking fraud on the victim’s phone. Bizarro includes keylogging, screen capture, clipboard hijacking for cryptocurrency theft, browser-session disruption, and extensive social engineering to obtain credentials and authentication codes. Grandoreiro provides remote access to victim machines, uses overlays to solicit one-time passwords and transaction credentials, monitors financial activity, supports keylogging and spam-sending through Outlook, and has evolved into a globally active banking trojan platform with restricted partner access resembling a closed affiliate model. Tetrade activity originated in Brazil and expanded well beyond Latin America into Europe, Africa, and other regions. Reported targeting includes Brazil, Mexico, Spain, Argentina, Portugal, Germany, Peru, Paraguay, Angola, Mozambique, France, Italy, Chile, the United Kingdom, the United States, India, and South Africa, among others. The actor cluster has shown sustained focus on financial institutions and related digital financial ecosystems, including banks, payment systems, exchanges, and crypto-wallet users. Its dominant motivation is financial gain.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 malware family attributed to this actor across reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Brazilian banking malware activity cluster associated with Grandoreiro, noted for sustained activity and global reach in financial malware operations.
Brazilian cybercrime umbrella associated here with Grandoreiro banking-trojan operations conducting fraudulent banking activity worldwide.
Referenced only as background comparison for Brazilian banking trojan operations.
Named banking-trojan activity cluster/family referenced as the broader grouping to which Guildma belongs; described as associated with expansion abroad and financial targeting.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.