The long-running Grandoreiro banking trojan is still actively targeting people and organizations in Latin America, Europe, and North America, with a recent campaign heavily aimed at Mexico. Acronis says recent Windows samples abuse the legitimate Duplicate Files Finder application for DLL sideloading, which loads malicious code through a trusted program, and use anti-analysis checks such as sandbox and virtual-machine detection before contacting command-and-control servers.
Why it matters: This is a sustained banking-malware campaign, not a one-off sample, and it keeps evolving to avoid detection. Organizations and users in affected regions should treat suspicious software downloads and banking-themed lures as high risk and review endpoint detections for DLL sideloading behavior.
Eduard Kovacs
2026.08.22
100% relevant
The article establishes a current campaign update with concrete targeting, delivery, and evasion details for Grandoreiro.
← Back to all stories