Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Over 500 Critical Infrastructure Organizations Hit by Medusa Ransomwar

August 20, 2026

Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

August 20, 2026

How Borussia Dortmund’s IT Chief Makes the Case for Cybersecurity

August 20, 2026
Facebook X (Twitter) Instagram
Thursday, August 20
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Grandoreiro Resurfaces in Mexico With New DLL Sideloading Campaign
News

Grandoreiro Resurfaces in Mexico With New DLL Sideloading Campaign

Team-CWDBy Team-CWDAugust 19, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Grandoreiro has resurfaced in a campaign targeting Latin American users, with Mexico accounting for 40% of observed detections and attackers using DLL sideloading to execute the banking trojan through legitimate software.

The Brazilian-origin malware remains active despite a major law-enforcement operation in January 2024 that disrupted parts of its infrastructure.

Acronis’ Threat Research Unit (TRU) observed the renewed campaign in May 2026, while telemetry from the last 30 days of June showed Mexico as the largest source of detected samples.

The findings add to previous Grandoreiro campaigns targeting Mexico and the malware’s earlier expansion into Spain.

Grandoreiro Abuses Legitimate Software

The latest campaign abused the legitimate Duplicate Files Finder application as part of a DLL sideloading chain. Attackers renamed the application and placed a malicious mingwm10.dll alongside legitimate dependencies, causing the trusted executable to load the malicious library.

The initial loader also used extensive anti-analysis checks. It looked for virtualization and sandbox artifacts, security and analysis tools, system characteristics and specific user and machine configurations before attempting to contact its command-and-control (C2) infrastructure.

It also checked the victim’s public IP address and geolocation, while traffic from several countries was blacklisted.

Acronis said the malware’s initial delivery vector could not be confirmed, although an invoice-like ZIP filename and Grandoreiro’s historical distribution patterns led them to assess with moderate confidence that spam had been involved.

The malware used encrypted strings to complicate analysis and contacted its C2 infrastructure only after completing its environmental checks. The C2 server was offline during the researchers’ analysis, but static examination indicated that the loader would attempt to retrieve a second-stage payload after establishing communication.

Mexico accounted for 40% of detections in the analyzed telemetry, followed by Spain at 17%, Peru at 13% and Argentina at 10%. Activity remained concentrated in Latin America, with smaller detection clusters in Europe and North America.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleSAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code
Next Article Exclusive: Linux Foundation’s Akrites to Go Live in September
Team-CWD
  • Website

Related Posts

News

Over 500 Critical Infrastructure Organizations Hit by Medusa Ransomwar

August 20, 2026
News

Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

August 20, 2026
News

OpenAI Tightens AI Safeguards Following Hugging Face Incident

August 19, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

All Major LLMs Exposed to Multi-Turn Manipulation, Warn Researchers

May 27, 20269 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Here’s how to avoid a ‘second strike’

April 11, 2026

How the always-on generation can level up their cybersecurity game

September 11, 2025

Managing risks to your loved one’s digital estate

April 2, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.