Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Grandoreiro goes north: From Brazil to Mexico with a new DLL sideloading campaign

0
Medium
Published: 08/19/2026 (08/19/2026, 20:39:08 UTC)
Source: AlienVault OTX General

Description

Grandoreiro is a banking trojan active since 2016 in Latin America, recently observed expanding operations from Brazil to Mexico. The malware campaign uses DLL sideloading by abusing the legitimate Duplicate Files Finder application to execute malicious code. It incorporates advanced anti-analysis techniques such as sandbox detection, virtual machine artifact checks, process blacklisting, and environment profiling to evade automated detection before contacting its command and control (C2) servers. Communication with C2 infrastructure occurs over TCP port 6432 using encrypted requests containing host-specific information. Telemetry from June 2026 shows activity mainly in Mexico, with some presence in Europe and North America.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/20/2026, 23:25:40 UTC

Technical Analysis

Grandoreiro is a longstanding banking trojan that continues active campaigns in Latin America despite law enforcement disruptions. The latest campaign leverages DLL sideloading by exploiting the legitimate Duplicate Files Finder application to load malicious payloads. The malware employs multiple anti-analysis mechanisms, including sandbox and virtual machine detection, process blacklisting, and environment profiling, prioritizing evasion before initiating C2 communication. It uses custom string obfuscation combining proprietary decryption with Base64 encoding. Communication with its C2 infrastructure is conducted over TCP port 6432 with encrypted requests that include host-specific data. The campaign's activity is concentrated in Mexico with limited activity in Europe and North America as of mid-2026.

Potential Impact

The malware enables unauthorized code execution on infected systems via DLL sideloading, potentially leading to credential theft and financial fraud targeting banking customers. Its advanced anti-analysis features complicate detection and analysis, increasing the difficulty of timely incident response. The encrypted C2 communication and host-specific data collection facilitate persistent and targeted operations. The geographic focus on Mexico and Latin America suggests regional targeting of financial institutions and users.

Defensive Guidance

No official patch or remediation is available as this is malware leveraging legitimate software abuse and advanced evasion techniques. Mitigation should focus on detecting and blocking DLL sideloading attempts, monitoring for suspicious use of Duplicate Files Finder, and employing behavioral detection capable of identifying sandbox evasion techniques. Network defenses should monitor and restrict outbound traffic on TCP port 6432 if not required by business processes. Endpoint detection and response (EDR) solutions with capabilities to detect obfuscated code execution and environment profiling behaviors are recommended. Users should be educated about phishing and social engineering tactics that may deliver this malware.

Affected Countries

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.acronis.com/en/tru/posts/grandoreiro-goes-north-from-brazil-to-mexico-with-a-new-dll-sideloading-campaign/"]
Adversary
null
Pulse Id
6a86146ca27454b03a4cbe2d
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domainvoyage.mydissent.net
domainbeeges.health-carereform.com
domainb744156103040828396040.nhlfan.net
domainstreamlinepdf-8m2x.workisboring.com
domain445675885304004.pointto.us
domainsmartpdfhub-7q2m.read-books.org

Hash

ValueDescriptionCopy
hash0fac99f58640171164d979d5529b00f8
hash320633a89e2f8b55cf45e4377bb8d041
hash48bf5850f83ac9bf7289b4473e0317b0
hash5d6cb9b58fcd2eb04da562d8249fc59f
hash629eea5fe09f79eefa74dccc9080cca3
hash82f771c3ec4fe979c3ae00372e8c3ac8
hash9d4842e9fb63f29fbea4c24105b2e39b
hash9e0c5ed2300a0362d91dc7a4e91be268
hashaf1a9545e70bbe2f372bb4e3b8ac8428
hashb5bcb465825423c03b5dff3d9979624b
hashc92684cd04f6ed3320c68c5fc7afbafa
hashcfbd8d062e9baa98737a0260996f48c6
hashe0e13f015af91741095b6fe16865f35d
hashe882ee4a643b00871c98bcfe4b4d7cd1
hashf0f428f7d9d4592ff018fd20b81d6134
hashf1aed8cf2adafa86927fc58d5f24073e
hash43847d704846c0438f010783d57a9e672c8ce904
hash545432aa95705bfe25e6b1a514d02ba0f2a050e1
hash588fbc54a7339b7840f1de8eb39fb0287c872cef
hash6272bbf3186a64e157f31880afbf4f86dca573dd
hash7bc79e8bbff363b41fd73f9bea102ddc4a404cbe
hashad4bcdda204d08f8c9003299e19a14694f1fc50e
hashb15c9a36fce2c61014d53fb86263565d8cf9a81c
hashb52de9c0457b039bf0888e661608ebffc0dc96ea
hashb9520fa1d972cc5c8aca07740838cf5410e09eb3
hashc2c1edb8370a36ffec6ad35fe27835009184713b
hashc571888b27c1bd42469976d4be43438d0c64b638
hashd5982202474dfb342720b6b022ed954cd73704ec
hashe6ae8be61928e1279190b0df28ac8ad94f3ac29d
hashf73391ddbdb0413e0e215e940b02f12e9d4a5667
hash1b2fe30c5bf57f9623efb34688580fe5bbb2c55351c5a07a6c4313bb6faa29f1
hash1fe5a72aefc38afeeee72d8a939f9db50800a447b7313f4d8c504771bb7fa2de
hash2820a2e36f1cb537a7853fde2313a5158d1e3696ff81c3066ec8fe274358c22d
hash368246eb503585f26e0151431909792b8d9be0edc229bb207be882bfb374c005
hash37492ecd9deb8591ea7e179ebb8e13c6b486cdacae18a6a482d9dd18f08453a3
hash47d5a73b220813299f753ef0a96582a8d08b853391864128a1f15271dbb42e65
hash609755a8c73e53f332428786c366323b3979850aaa0e075d946e6c05aa62f867
hash65db035f79db85ad66fb3e0365e478f95f8f648545b18360d850a7ed179c9dab
hash684f5eb157ef2ba3ea17335d6c8c9c801f93e6eb3aa08ecbfaf5806a4b5e3b80
hash98e56c5f902fb825f6f122122ba6a2a0febee1e582a462f74dd1d99b018bf7c0
hasha91c7cb932301454df4b0feed58082cae7f2d0e4078d7e6df3f53d806ed04f1d
hashac35843c81381107d4f816681477d706c43fa75f064f2c3d99237c7282f0b798
hashad5762fa98da2aff24d9d6b55be5dae21d07c54679ead67252a19c2521162a87
hashc019cfa9b50a69ff07e98bd78b3a6fc489110e5db1c0d79ada716605a2320951
hashca33f5608b72ecca64a002074a4103c7cb83de902ecf5c69949eecb7eef03b5a
hashcc238813ab277cbb4324d37875c37985ca5baeaf8c412b4c85aa8ec5faec7096
hashe0491eddb45425a674e479b2590517ffef2f108add431761bb89791fc208b6e9
hashe99416ff71e4574de4fceebdc34f3b9a6e0610f36b77b735b231bd39edb7a0a1
hashfad1e9d507c7021a62998a547ab53b3ee438846f7ae753285fdb3917dd2dcdfa

Threat ID: 6a8788a0acd9273b493f8bef

Added to database: 08/20/2026, 23:07:12 UTC

Last enriched: 08/20/2026, 23:25:40 UTC

Last updated: 08/20/2026, 23:25:40 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses