www.infosecurity-magazine.com 8/19/2026, 2:02:21 PM · external

Grandoreiro Trojan Returns in Mexico via DLL Sideloading Trick

Grandoreiro Trojan Returns in Mexico via DLL Sideloading Trick
CyberSIXT Evidence Panel Source marked as original reporting

THE article discusses the resurgence of the Grandoreiro banking trojan in Mexico, where it has been linked to DLL sideloading via legitimate software, specifically the Duplicate Files Finder application. Observations indicate that 40% of the malware's detections occur in Mexico, followed by Spain, Peru, and Argentina. Despite a major law enforcement operation in early 2024 that disrupted its infrastructure, Grandoreiro remains active and evolving. The malware uses sophisticated anti-analysis checks and encrypted strings for obfuscation, complicating efforts to understand its operations.

View full article

Article by CyberSIXT