Grandoreiro Banking Trojan Resurfaces, Targeting Over 1,500 Banks Worldwide
May 19, 2024
Banking Troja /  Email Security
 The threat actors behind the Windows-based  Grandoreiro  banking trojan have returned in a global campaign since March 2024 following a law enforcement takedown in January.  The large-scale phishing attacks, likely facilitated by other cybercriminals via a malware-as-a-service (MaaS) model, target over 1,500 banks across the world, spanning more than 60 countries in Central and South America, Africa, Europe, and the Indo-Pacific, IBM X-Force said.  While  Grandoreiro  is known primarily for its focus in Latin America, Spain, and Portugal, the expansion is likely a shift in strategy after attempts to  shut down its infrastructure  by Brazilian authorities.  Going hand-in-hand with the broader targeting footprint are significant improvements to the malware itself, which indicates active development.   "Analysis of the malware revealed major updates within the string decryption and domain generating algorithm (DGA), as well as the ability to use Mic...