A recent report by Acronis identifies the resurgence of the Grandoreiro banking trojan, which targets bank users in Mexico, Spain, Peru, and Argentina. This malware campaign utilizes DLL sideloading through an invoice-themed email attachment, featuring a disguised legitimate application to load malicious code. Grandoreiro has persisted despite law enforcement actions that disrupted its operations in 2024.
Key tactics include evasion measures against analysis tools and a sophisticated command-and-control process for data theft. Victim detection highlights Mexico as the primary target, followed by Spain, Peru, and Argentina. Recommendations for defense focus on monitoring for unusual DLL loading from trusted applications and blocking suspicious email attachments.