Grandoreiro banking trojan campaign keeps targeting Mexico, Latin America, Europe, and North America with DLL sideloading

The long-running Grandoreiro banking trojan is still actively targeting people and organizations in Latin America, Europe, and North America, with a recent campaign heavily aimed at Mexico. Acronis says recent Windows samples abuse the legitimate Duplicate Files Finder application for DLL sideloading, which loads malicious code through a trusted program, and use anti-analysis checks such as sandbox and virtual-machine detection before contacting command-and-control servers.
Why it matters: This is a sustained banking-malware campaign, not a one-off sample, and it keeps evolving to avoid detection. Organizations and users in affected regions should treat suspicious software downloads and banking-themed lures as high risk and review endpoint detections for DLL sideloading behavior.

Sources

Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight
Eduard Kovacs 2026.08.22 100% relevant
The article establishes a current campaign update with concrete targeting, delivery, and evasion details for Grandoreiro.
← Back to all stories