CyberSecurity SEE

Grandoreiro Emerges in Mexico with New DLL Sideloading Campaign

Grandoreiro Emerges in Mexico with New DLL Sideloading Campaign

Resurgence of Grandoreiro: Targeting Latin American Users with Malicious Techniques

The infamous banking trojan Grandoreiro has made a notable resurgence in a campaign specifically targeting users in Latin America, with a staggering 40% of all observed detections originating from Mexico. This alarming resurgence highlights the ongoing threat posed by the malicious software, which employs advanced tactics, such as DLL sideloading, to execute its harmful payloads through seemingly legitimate software.

Despite the significant law-enforcement operation in January 2024, which successfully disrupted various components of Grandoreiro’s operational infrastructure, the malware continues to remain active and poses a considerable risk. The Brazilian-origin malware has not only persisted but has also adapted its methods, as evidenced by its renewed campaign first identified by Acronis’ Threat Research Unit (TRU) in May 2026. Further analysis of telemetry data gathered from the last 30 days of June confirmed that Mexico is, once again, at the epicenter of this malicious activity.

Acronis’ findings not only showcase Grandoreiro’s recent resurgence but also build upon previous efforts by the malware to target Mexico, as well as its earlier incursions into the Spanish market. The significance of these ongoing campaigns underlines the need for heightened awareness among users in these regions, especially given the scale and reach of the operation.

Exploiting Legitimate Software: A Malicious Strategy

In the newest campaign, the attackers have resorted to abusing legitimate software, particularly the Duplicate Files Finder application, as part of a sophisticated DLL sideloading chain. This process involves renaming the legitimate application and dropping a malicious mingwm10.dll file alongside the authorized dependencies. As a result, the trusted executable is tricked into loading the harmful library, which enables the malware to execute its malicious functions without raising immediate suspicion.

The initial loader utilized by the attackers is remarkably sophisticated, equipped with a range of anti-analysis checks. This includes scrutinizing system characteristics, identifying virtualization and sandbox artifacts, as well as analyzing specific user and machine configurations. Such meticulous checks are integral to the exploit’s success, as they ensure the malware can evade detection and bypass security measures put in place by victims and cybersecurity professionals alike.

Additionally, the malware goes a step further by checking the victim’s public IP address and geolocation, deliberately blacklisting traffic from certain countries to refine its targeting and enhance its stealth capabilities. This layer of precaution indicates a level of sophistication that underscores the threat posed by Grandoreiro.

While Acronis noted that the exact delivery vector used for this campaign couldn’t be definitively confirmed, the researchers speculated with moderate confidence that spam emails may have played a role, given the use of invoice-like ZIP filenames consistent with Grandoreiro’s historical distribution methods.

Encrypted Communications and Target Patterns

Another notable aspect of the malware’s functionality is its use of encrypted strings, which complicate analysis and hinder detection efforts. The loader is designed to establish communication with its command-and-control (C2) infrastructure only after completing the aforementioned environmental checks. During the analysis conducted by Acronis, the C2 server appeared to be offline, yet static examination revealed that it would typically attempt to retrieve a second-stage payload once communication was successfully established.

In the telemetry data analyzed, the dominance of Mexico was stark, accounting for 40% of the detections related to Grandoreiro. This was followed by Spain at 17%, Peru at 13%, and Argentina at 10%, indicating that Latin America remains the primary battleground for these malicious attacks. Although the malware’s activity is concentrated in this region, cybersecurity experts have noted smaller detection clusters in parts of Europe and North America.

The reemergence of Grandoreiro serves as a stark reminder of the persistent threats posed by cybercriminals, particularly in Latin America. As users become increasingly reliant on digital services, the need for robust cybersecurity measures and increased awareness remains paramount to thwart such sophisticated attacks. Organizations and individuals alike are urged to remain vigilant, fortifying their defenses against the evolving tactics employed by malware such as Grandoreiro. The trajectory of this banking trojan underscores not only the resilience of cyber threats but also the necessity for ongoing adaptation in cybersecurity strategies.

Source link

Exit mobile version