Grandoreiro Malware Expands Across Regions
Grandoreiro malware continues to target users across Europe and Latin America. Researchers recently identified new campaigns affecting multiple countries. The attacks focus on both businesses and financial institutions. In addition, cybercriminals target users who rely on online banking services. Therefore, the threat remains a major concern.
Researchers observed attacks in Spain, Portugal, and Mexico. Meanwhile, Android users in Brazil also faced related threats. The malware operators continue to improve their techniques. As a result, security teams face increasing challenges. Furthermore, the attacks now use more advanced evasion methods.
DLL Side-Loading Helps Hide Malware
The latest Grandoreiro campaign relies on DLL side-loading. This technique allows malware to run through trusted software. Therefore, attackers can avoid basic security controls. Researchers found several malicious DLL files involved in the attacks. In addition, these files help maintain hidden communications.
Some of the files use technologies designed for peer-to-peer communication. For example, they rely on protocols that help devices connect directly. As a result, attackers can exchange data more discreetly. Furthermore, these communication methods resemble normal internet traffic. Therefore, detecting malicious activity becomes more difficult.
Banking Institutions Remain Primary Targets
The campaign focuses heavily on financial organizations. Researchers found references to several banking services within the malware. These references suggest careful target selection. In addition, attackers appear interested in digital banking platforms. Therefore, both traditional and modern financial services face risks.
The malware seeks banking credentials and sensitive information. Once attackers gain access, they can steal valuable data. Furthermore, stolen credentials may enable fraudulent transactions. As a result, victims may suffer financial losses. Therefore, protecting banking information remains essential.
Phishing Emails Drive New Infections
Researchers also uncovered a separate phishing campaign. Attackers send emails containing links to malicious files. For example, victims receive compressed archives hosted online. These files contain scripts designed to launch malware. Consequently, unsuspecting users may infect their systems.
The attack displays a fake software update message. However, the alert serves only as a lure. If users click the update button, additional malware loads. Furthermore, the infection process includes several security checks. Therefore, analysis and detection become more difficult.
Cybercriminals Continue to Adapt
Researchers noted that Grandoreiro remains highly active. Despite previous law enforcement actions, the malware continues evolving. In addition, attackers frequently adopt new techniques. Therefore, security defenses must also improve. Simple protection measures may no longer be enough.
The campaign combines phishing, cloud services, and stealth methods. Furthermore, it uses communication tools that many organizations trust. As a result, malicious traffic may blend with legitimate activity. Therefore, attackers can remain hidden for longer periods. This trend increases overall cyber risk.
BTMOB RAT Threatens Android Users
A second campaign involves BTMOB, an Android remote access trojan. Researchers first identified this malware in early 2025. Since then, it has gained several new capabilities. For example, it can capture screenshots and record keystrokes. Therefore, attackers can gather highly sensitive information.
The malware also supports remote device control. In addition, it can steal credentials through fake login screens. Researchers discovered features that target financial applications. Consequently, mobile banking users face significant risks. Furthermore, attackers continue improving the malware.
Malware-as-a-Service Increases the Threat
Researchers found that BTMOB follows a malware-as-a-service model. This approach allows other criminals to use the malware easily. For example, buyers can create customized attack packages. Therefore, even less skilled attackers can launch campaigns.
The malware includes tools that simplify deployment. In addition, operators can customize phishing pages quickly. As a result, attacks can spread faster across regions. Furthermore, leaked versions reportedly circulate online. Therefore, the risk of copycat attacks continues to grow.
Fake Websites Trick Victims
BTMOB primarily spreads through social engineering tactics. Attackers create fake websites that mimic trusted services. For example, they imitate streaming platforms and financial services. Victims then receive links directing them to these pages. Consequently, many users believe the websites are legitimate.
The fake sites encourage users to install malicious applications. Once installed, the malware requests accessibility permissions. It then abuses those permissions to gain deeper access. Furthermore, users often remain unaware of the compromise. Therefore, attackers can maintain control for extended periods.
Why Mobile Banking Threats Are Growing
Mobile devices store large amounts of sensitive information. Therefore, they have become valuable targets for cybercriminals. Banking credentials, personal messages, and authentication data often reside on smartphones. As a result, successful attacks can cause serious harm.
Researchers warn that Android malware continues evolving rapidly. In addition, malware developers now offer subscription-based services. This business model lowers entry barriers for criminals. Consequently, more threat actors can launch sophisticated attacks. Therefore, mobile security remains a critical priority.
How to Prevent Banking Malware Attacks
Organizations and users should combine awareness with strong security controls. Regular security assessments can identify weaknesses before attackers exploit them. In addition, managed detection and response services can help detect suspicious behavior early. Organizations should also monitor endpoints continuously and educate users about phishing risks.
Furthermore, strong access controls and threat monitoring improve visibility and reduce the chance of successful malware infections.
Sleep well, we got you covered.

