No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

‘Grandoreiro’ Trojan Targets Global Banking Customers

October 24, 2023
in Protection
0
informa



The Brazilian banking malware known as “Grandoreiro” has crossed the pond, with a new campaign from TA2725 targeting customers in Spain, as well as Brazil and Mexico. 

Dark Web activity in Latin America has surged in the last two years, and it’s largely concentrated in two countries. According to SOCRadar, 360 billion attempted cyberattacks peppered the region in 2022, with 187 billion and 103 billion affecting Mexico and Brazil, respectively.

Now there’s increasing evidence that Latin American cybercrime is extending outwards.

Proofpoint has tracked TA2725 since March 2022. It’s been known to hide bank account and credit card-sniffing malware inside of phishing emails, primarily directed to organizations either in its home country or Mexico. And according to a new blog post by Jared Peck, senior threat researcher at Proofpoint, the group has recently upgraded its signature malware to include institutions on both sides of the Atlantic.

Brazilian Malware in Spain

Grandoreiro attacks begin with a malicious URL in a phishing email. Lures may come in the form of a fake shared document, utility bill, tax form, etc. The URL leads to a ZIP file containing a loader which, when run, downloads a legitimate but vulnerable application. The application is exploited with some DLL sideloading, and then comes the final payload.

Grandoreiro can harvest data via a keylogger, screen grabber, or an old-fashioned overlay on top of an online banking login page. These overlays mimic popular Brazilian and Mexican banks plus, in two campaigns observed late in August, banks located in Spain. (TA2725’s phishing lures were also diversified, to mimic Spain-based organizations.)

This isn’t the first time Brazilian Trojans have spanned the Atlantic. Earlier this year, for example, threat actors pulled a reverse Pedro Cabal, subjugating Portuguese bank customers in a campaign called “Operation Magalenha.” This latest activity only furthers an emerging trend — that Brazilian malware is no longer contained to one continent.

Why Brazilian Cybercrime Is Having a Moment

Where once they seemed solely the domain of the northern hemisphere, banking trojans have thrived in Brazil in recent years. According to Peck, there are a few reasons why.

“The general population in many parts of the world, like Brazil and other parts of South America and Latin America, may not have been afforded the same access to cybersecurity education and protection technology as other parts of the world, but continue to grow their online presence. This situation leads to a lack of user awareness around phishing and malware threats, which, in turn, leads to a higher number of victims who click and are affected,” he explains, adding that “this general population is upwardly mobile, leading to a larger middle class, so there is more opportunity to victimize a larger pool of a population.”

According to Proofpoint, the most common malware families — including Grandoreiro but also, Casabeniero, Javali, and Mekotio — possess a shared lineage: a Delphi-based ancestor from which source code components have been passed down and modified through generations.

Organizations in affected countries can look out for suspicious programs with these same elements. Or, as Peck emphasizes, they can focus on the human side of such compromises.

“Today’s cyber threats rely on human interaction, not just technical exploits, so it is essential that organizations incorporate localized user security awareness training on identifying malicious phishing and threat actor tactics, techniques, and procedures while also empowering users to feel comfortable reporting their suspicions even after they may have fallen victim to an attack,” he advises.

Editorial Team

Editorial Team

Related Posts

I Tried Strava's New 'Instant Workouts' Feature, and It Isn't Great
Protection

I Tried Strava’s New ‘Instant Workouts’ Feature, and It Isn’t Great

January 22, 2026
Apple Might Turn Siri Into an AI Chatbot to Rival ChatGPT
Protection

Apple Might Turn Siri Into an AI Chatbot to Rival ChatGPT

January 22, 2026
The P Water Hydration App Tracks Your 'Output' Instead of Your Intake
Protection

The P Water Hydration App Tracks Your ‘Output’ Instead of Your Intake

January 21, 2026
The Emergency Repair Supplies Every Homeowner Should Have on Hand
Protection

The Emergency Repair Supplies Every Homeowner Should Have on Hand

January 21, 2026
Google Just Promised No Ads in Gemini (for Now)
Protection

Google Just Promised No Ads in Gemini (for Now)

January 21, 2026
This 'Ad Blocker' Actually Initiates ClickFix Attacks
Protection

This ‘Ad Blocker’ Actually Initiates ClickFix Attacks

January 21, 2026
Load More
Next Post
Bitcoin Hits $35,000 for First Time Since 2022 on ETF Optimism

Bitcoin Hits $35,000 for First Time Since 2022 on ETF Optimism

Popular News

  • Josh Garber

    How to Contact Hilton Customer Service

    0 shares
    Share 0 Tweet 0
  • Cybersecurity dominates concerns among the C-suite, small businesses and the nation

    0 shares
    Share 0 Tweet 0
  • Cash Sweep Accounts vs. Money Market Funds, HYSAs & CDs

    0 shares
    Share 0 Tweet 0
  • 5 Things to Know About the Seen Mastercard

    0 shares
    Share 0 Tweet 0
  • TAP Airline Portugal Partners: What to Know

    0 shares
    Share 0 Tweet 0

Latest News

After vanishing from view, two US-seized Venezuela oil tankers reappear near Puerto Rico

After vanishing from view, two US-seized Venezuela oil tankers reappear near Puerto Rico

January 22, 2026
0

After vanishing from view, two US-seized Venezuela oil tankers reappear near Puerto Rico

Ondo Brings 200+ Tokenized Stocks to Solana, Challenging xStocks Dominance

Ondo Brings 200+ Tokenized Stocks to Solana, Challenging xStocks Dominance

January 22, 2026
0

Key NotesOndo's platform allows instant token creation during US market hours, sourcing liquidity directly from major exchanges.xStocks has processed over...

Trump’s tariff reversal sparked a market rally — but the violent swing in stocks is a warning of what lies ahead for investors

Trump’s tariff reversal sparked a market rally — but the violent swing in stocks is a warning of what lies ahead for investors

January 22, 2026
0

Investors are getting accustomed to a familiar pattern known on Wall Street as ‘TACO’ — the assumption that the president...

I Tried Strava's New 'Instant Workouts' Feature, and It Isn't Great

I Tried Strava’s New ‘Instant Workouts’ Feature, and It Isn’t Great

January 22, 2026
0

Earlier this month Strava unveiled its new Instant Workouts feature, a subscriber-exclusive tool that seems like a natural way to...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.