THE article discusses the resurgence of the Grandoreiro banking trojan in Mexico, where it has been linked to DLL sideloading via legitimate software, specifically the Duplicate Files Finder application. Observations indicate that 40% of the malware's detections occur in Mexico, followed by Spain, Peru, and Argentina. Despite a major law enforcement operation in early 2024 that disrupted its infrastructure, Grandoreiro remains active and evolving. The malware uses sophisticated anti-analysis checks and encrypted strings for obfuscation, complicating efforts to understand its operations.
Grandoreiro Trojan Returns in Mexico via DLL Sideloading Trick
CyberSIXT Evidence Panel
Source marked as original reporting
Article by CyberSIXT