securityonline.info 8/26/2026, 8:32:27 AM · external

Grandoreiro trojan resurges via invoice email DLL sideload scheme

Grandoreiro trojan resurges via invoice email DLL sideload scheme
Developing story malware 3 articles tracked
Grandoreiro, Manic, and ToxicPanda 2.0 banking trojans active worldwide
CyberSIXT Evidence Panel
Primary Source acronis.com

A recent report by Acronis identifies the resurgence of the Grandoreiro banking trojan, which targets bank users in Mexico, Spain, Peru, and Argentina. This malware campaign utilizes DLL sideloading through an invoice-themed email attachment, featuring a disguised legitimate application to load malicious code. Grandoreiro has persisted despite law enforcement actions that disrupted its operations in 2024.

Key tactics include evasion measures against analysis tools and a sophisticated command-and-control process for data theft. Victim detection highlights Mexico as the primary target, followed by Spain, Peru, and Argentina. Recommendations for defense focus on monitoring for unusual DLL loading from trusted applications and blocking suspicious email attachments.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline