Grandoreiro is a Brazilian-origin Windows banking trojan written in Delphi and active since at least 2016. It targets financial institutions and their customers, historically concentrating on Latin America before expanding into Europe and North America. Its capabilities include stealing banking credentials and financial information, extracting saved credentials and cookies from Google Chrome, logging keystrokes, screen sharing, and remotely controlling infected systems. It collects host and user information, identifies installed security products, determines public IP addresses and geographic location, and sends collected data to command-and-control infrastructure. Distribution has included malicious links in emails and malicious attachments.
A campaign observed in May 2026 used DLL sideloading through a renamed copy of the legitimate Duplicate Files Finder application to execute a protected loader. The loader hides the application's window and performs extensive environmental checks before contacting command-and-control infrastructure. These checks examine system uptime, hardware resources, screen resolution, user activity, virtualization artifacts, running analysis tools, and host identifiers. Geographic filtering and encrypted internal strings provide additional evasion. After validation, the loader uses DNS-over-HTTPS to resolve its command-and-control destination and attempts to retrieve an encrypted second-stage payload, transmitting host information including usernames, computer names, and security-product details.
Grandoreiro remained active after a January 2024 disruption involving Brazilian and Spanish authorities and INTERPOL, although subsequent activity was below earlier peaks. Its 2026 campaigns continued to concentrate on Latin America, particularly Mexico, with additional detections in Spain, Peru, Argentina, and smaller clusters elsewhere in Europe and North America.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A new version of Grandoreiro malware from TA2725 targets both Mexico and Spain. Previously this malware has only targeted victims in Brazil and Mexico.
In 2025, Brazilian-origin families such as Grandoreiro (part of the Tetrade group) stood out for their constant activity and global reach. Despite a major law enforcement disruption in early 2024, Grandoreiro remained active in 2025, re-emerging with updated variants and continuing to operate.
43 distinct techniques documented for this family, organized by ATT&CK tactic.
208 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
132 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Grandoreiro is a banking trojan active since at least 2016 that targets bank users. In this campaign it is delivered with suspected invoice-themed spam ZIP archives, uses DLL sideloading via a renamed legitimate application, checks for analysis environments and security tools, and—after passing those checks—uses Google's DNS-over-HTTPS resolver to contact C2 and request an encrypted second-stage payload while sending host profiling data.
Grandoreiro is identified as a banking trojan whose activity has reactivated in Latin America.
Banking trojan identified as active in Mexico.
Long-running Windows banking trojan of Brazilian origin targeting users in Latin America, Europe, and North America. Recent samples abuse the legitimate Duplicate Files Finder application for DLL sideloading and include extensive anti-analysis and sandbox-evasion checks before contacting C2 infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.