FlagThis — Daily Cybersecurity Intelligence Briefing

FILTERING BY: CLEAR FILTER

Grandoreiro and BTMOB: Multi-Platform Evolution and Tactical Resurgence Against Lusophone and Latin American Financial Sectors

The Grandoreiro malware family has undergone a significant tactical pivot, transitioning from a specialized Windows-based banking trojan to a sophisticated, multi-platform threat ecosystem. Following recent law enforcement-led disruptions by INTERPOL, threat actors have demonstrated high resilience, re-emerging with a more versatile payload architecture: 'Grandoreiro Light,' a lightweight infostealer designed for rapid credential and data exfiltration, and a coordinated mobile component utilizing the BTMOB Android RAT. This dual-platform approach targets both desktop environments via advanced Windows injection techniques and mobile devices via Android-based infection vectors, specifically aiming at financial institutions and corporate infrastructures in Brazil, Portugal, Spain, and Mexico. The evolution marks a shift from pure transaction interception to comprehensive account takeover (ATO) and lateral movement across diverse device environments.


LINK COPIED TO CLIPBOARD