Grandoreiro, the global trojan with grandiose goals


Grandoreiro is a well-known Brazilian banking trojan — part of the Tetrade umbrella — that enables threat actors to perform fraudulent banking operations by using the victim’s computer to bypass the security measures of banking institutions.

It’s been active since at least 2016 and is now one of the most widespread banking trojans globally. INTERPOL and law enforcement agencies across the globe are fighting against Grandoreiro, and Kaspersky is cooperating with them, sharing TTPs and IoCs. However, despite the disruption of some local operators of this trojan in 2021 and 2024, and the arrest of gang members in Spain, Brazil, and Argentina, they’re still active. Kaspersky researchers are now know for sure that only part of this gang was arrested: the remaining operators behind Grandoreiro continue attacking users all over the world, further developing new malware and establishing new infrastructure.

Read more…
Source: Kaspersky


Sign up for our Newsletter


Related:

  • LG TV flaws could let attackers listen in, even in standby mode

    September 7, 2026

    Smart TVs are internet-connected computers with microphones, app stores, advertising systems, and access to the same home networks used by your family’s phones, laptops, printers, and smart-home devices. In the past, we reported on Samsung settling a lawsuit with the Texas Attorney General over how its smart TVs collect and monetize viewing data using Automated Content Recognition (ACR). ACR technology samples what appears ...

  • US military disabled ad tracking on troops’ devices following reports of targeted attacks

    September 4, 2026

    The U.S. Department of Defense has disabled advertising tracking on troops’ phones and computers as part of an effort to protect them from threats that target their locations, according to a letter shared with Sen. Ron Wyden. Per a letter shared with the senior Democrat on the Senate Intelligence Committee, Wyden said that the U.S. Army, ...

  • Angry Birds: Toy Ghouls’ new toys

    September 4, 2026

    Kaspersky continue tracking the activity of Toy Ghouls (also known as Bearlyfy, Laboo.boo, and Feral Wolf), a financially motivated group that has been targeting Russian organizations since 2025. The attackers initially relied exclusively on tools pulled from public GitHub repositories along with leaked Babuk and LockBit ransomware builders, later shifting to their own custom ransomware, GenieLocker. In ...

  • Free streaming boxes may be routing criminal traffic through your home

    September 4, 2026

    “Free” movies and TV could cost you your privacy, bandwidth, and control of your home network. We’ve warned about illegal streaming and modded Amazon Fire TV Sticks in the past. Now, researchers have found that certain SuperBox devices and apps could quietly enroll a household connection into a proxy network, allowing third parties to route traffic through it. An earlier report identified CyberFlix ...

  • Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America

    September 3, 2026

    We have analyzed two ongoing, multi-stage network intrusion and data-exfiltration campaigns targeting organizations in Latin America. Corroborating recent findings from the broader threat intelligence community, we observed attackers leveraging artificial intelligence (AI) to enhance their capabilities. Read more… Source:  Palo Alto Unit 42 Sign up for the Cyber Security Review Newsletter The latest cyber security news and insights delivered ...

  • SonicWall’s SMA1000 boxes under active attack again

    September 2, 2026

    SonicWall says attackers are actively exploiting two chained zero-days to take over Secure Mobile Access (SMA) Series 1000 boxes. Aimed at midsize and large enterprises, SMA1000 gateways secure remote access and VPN connections. Compromising one can therefore provide attackers with a valuable route into corporate networks. So, get to applying those hotfixes, says SonicWall. There are no ...