LIVE · cybersecurity feed
Live wire
'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllersNSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technologyUS warns of AI-powered attacks on Siemens PLCs in critical infrastructureCVE-2026-19490 · CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler GatewayA California county wants to hire Tina Peters to help run its electionsThe long tail of Clop’s PTC hack is just beginning to emergeOracle Critical Patch Update, August 2026 Security Update ReviewMedusa ransomware gang has hit over 500 organizations, CISA warnsCritical RCE flaw in Windows IKE Extension now actively exploitedOracle August 2026 Critical Security Patch Update Addresses 925 CVEs
security

Grandoreiro Resurfaces in Mexico With New DLL Sideloading Campaign

Grandoreiro is active after its 2024 disruption, with Mexico now accounting for 40% of detections

zeroday.news ·

The Grandoreiro banking trojan has re-emerged in a new campaign primarily targeting users in Latin America, with Mexico accounting for the largest share of detected activity. This resurgence follows a law enforcement operation in January 2024 that disrupted portions of the malware's infrastructure.

Researchers from Acronis’ Threat Research Unit (TRU) observed the renewed campaign beginning in May 2026. Telemetry data from June 2026 indicated that Mexico was the source of 40% of detected samples, followed by Spain at 17%, Peru at 13%, and Argentina at 10%. While activity remains concentrated in Latin America, smaller clusters of detections were also noted in Europe and North America.

The latest campaign leverages DLL sideloading to execute the Grandoreiro trojan. Attackers are abusing the legitimate "Duplicate Files Finder" application, renaming it and placing a malicious `mingwm10.dll` file alongside its genuine dependencies. This technique causes the trusted executable to load the malicious library, facilitating the malware's execution.

Before attempting to connect to its command-and-control (C2) infrastructure, the initial loader incorporates extensive anti-analysis checks. These checks scan for virtualization and sandbox environments, security tools, system characteristics, and specific user and machine configurations. The malware also verifies the victim's public IP address and geolocation, with traffic from certain countries being blacklisted.

While the precise initial delivery vector could not be definitively confirmed by researchers, an invoice-like ZIP filename and Grandoreiro's historical distribution patterns led to a moderate confidence assessment that spam was involved. The malware employs encrypted strings to further complicate analysis.

During the researchers' analysis, the C2 server was offline. However, static examination of the malware indicated that the loader was designed to retrieve a second-stage payload once communication with the C2 server was established.

Despite the 2024 infrastructure disruption, overall Grandoreiro activity, though below its previous peak, continues to evolve. This indicates that the operation behind the banking trojan remains active and is adapting its tactics.

ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

Smashing Security podcast #481: Never say this to a robot dog

At Black Hat this month, a group of security researchers took a $9,000 robot dog, plugged Google's AI into its brain, and jailbroke it by telling it - with a completely straight face - that it was a Pokemon. What followed involved a wall, a blue ice chest, and anyone in the room wearing white shoes. Oh, and did we mention you can buy a flamethrower attachment? Meanwhile, in Salzburg, 280 gold stat

aicritical

'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers

'It is an active threat'

ransomware

Rogue ransomware affiliate poses as data recovery firm to steal payments

A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. [...]

cloud

Sakura Internet hack exposes data of up to 1.36 million accounts

Japanese cloud and data center service provider Sakura Internet disclosed that hackers accessed its sales management system, where customer contract and membership information is stored. [...]

breach

Healthtech firm CareCloud data breach impacts 3.7 million patients

U.S. healthcare IT company CareCloud disclosed that the data breach incident it suffered earlier this year has impacted more than 3.7 million individuals. [...]

ai

AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn

The agencies said the hackers are taking aim at Siemens S7 Series programmable logic controllers in what could be a first. The post AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn appeared first on CyberScoop.