HackMyIP
← Back to News
2026-08-20 Dark Reading

Grandoreiro Banking Trojan Resurfaces in Mexico with New Evasion Tactics

MalwareThreat Intel

The Grandoreiro banking Trojan, one of Latin America's most prolific financial malware families, has resurfaced in a fresh campaign targeting Mexican financial institutions. According to researchers tracking the threat, operators linked to the Brazil-based cybercrime group have retooled the malware with enhanced anti-analysis features and updated command-and-control infrastructure following a high-profile international law enforcement takedown earlier this year. The renewed activity signals that the threat actors behind Grandoreiro remain operational despite coordinated disruption efforts by authorities in Brazil, Spain, and across Europe.

The updated variant introduces several technical improvements designed to frustrate reverse engineering and evade sandbox environments. Researchers noted the malware now employs heavy string obfuscation, dynamic API resolution, and delayed execution logic to bypass automated analysis tools. Its C2 communication has also been overhauled to use encrypted HTTPS channels with certificate pinning, making network-level detection significantly harder. Security teams investigating suspicious traffic patterns can use a SSL/TLS checker to validate certificate chains on endpoints potentially communicating with malicious infrastructure. The Trojan also deploys a lightweight browser fingerprint test module on infected hosts, fingerprinting the victim's system and browser configuration before overlaying phishing pages on legitimate banking portals.

Grandoreiro's primary attack vector remains spear-phishing emails impersonating Mexican tax authorities, telecom providers, and banking institutions. Once executed, the loader performs environment checks and establishes persistence through Windows registry run keys. The malware then injects code into legitimate browser processes, monitors victim navigation, and triggers web injects when users access targeted bank URLs. Stolen credentials and session cookies are exfiltrated to attacker-controlled servers, often enabling fraudulent wire transfers and account takeovers within hours of compromise.

Security teams defending against Grandoreiro and similar Latin American banking Trojans should prioritize email gateway filtering, endpoint detection rules targeting registry persistence, and network monitoring for anomalous TLS connections to non-corporate domains. Organizations operating in the financial sector across Mexico and Latin America are advised to conduct a privacy checkup across employee systems and review recent phishing reports. Given Grandoreiro's history of rebranding and tactical adaptation, researchers expect the group to continue iterating on its toolset as defenders close off existing infrastructure.

Source: Dark Reading →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →