Loading article…
The Grandoreiro banking trojan has resurfaced with a new campaign targeting Mexico, which accounts for 40% of recent detections despite 2024 law enforcement.
Mexico currently accounts for 40% of all detected Grandoreiro banking trojan activity, marking a significant resurgence for the malware despite a major international law enforcement disruption in January 2024 [1]. The campaign, which relies on sophisticated DLL sideloading to bypass security, poses a persistent threat to financial institutions and their customers across Latin America and beyond [3].
| At a glance | |
|---|---|
| Mexico Detection Share | 40% of total activity |
| Primary Target Regions | Latin America, Spain, Europe |
| Malware Origin | Brazil (circa 2016) |
| Known Bank Targets | Over 1,500 institutions |
The latest campaign, observed by researchers in May 2026, utilizes a legitimate file-management tool, Duplicate Files Finder, to execute malicious code [1]. By renaming the application and placing a malicious library alongside it, attackers successfully employ DLL sideloading to trigger the trojan while appearing as a trusted process [3]. This method is paired with extensive anti-analysis features, including checks for virtualization, sandbox environments, and nearly 50 distinct security or monitoring tools, which the malware scans for before establishing contact with its command-and-control infrastructure [1].
While the malware's overall activity remains below its historical peak, the current campaign demonstrates a shift toward more stealthy, modular deployment [1]. Researchers note that the operators have moved away from simple distribution, instead using invoice-themed ZIP files to trick users into installing the payload [3]. This strategy follows a broader trend of "malware-as-a-service" operations, which have allowed the trojan to persist by fragmenting its codebase into smaller, more difficult-to-detect versions [3].
Although the malware originated in Brazil and remains heavily concentrated in Spanish-speaking regions, its reach has expanded significantly since its 2016 inception [3]. Recent telemetry shows that while Mexico leads with 40% of detections, Spain follows at 17%, Peru at 13%, and Argentina at 10% [1]. The trojan is designed to steal banking credentials through keystroke logging, screen sharing, and remote device control, targeting more than 1,500 banks across over 60 countries [2].
The persistence of the threat suggests that the 2024 law enforcement operation, which resulted in the arrest of five administrators, did not fully dismantle the underlying infrastructure [3]. Instead, the operators have adapted by impersonating various government entities, including tax and finance authorities in Mexico, Argentina, and South Africa, to increase the effectiveness of their phishing campaigns [2].
The ability of the Grandoreiro operation to reorganize after high-profile arrests highlights the resilience of modern, decentralized cybercrime networks. Whether this latest campaign represents a permanent shift in strategy or a temporary surge remains an open question for financial security teams.
Coverage is mostly measured — 247 of 268 reports stay neutral.
Every Monday — the token unlocks, Fed dates & catalysts set to move crypto and markets this week. So you’re never blindsided.
Free · 3-min read · one-click unsubscribe
AI-assisted synthesis by the TrendWatcher Editorial Desk · sourced from 4 outlets · Aug 21, 2026 · How we report
There are currently four US banks in the 'trillion-dollar club': JPMorganChase, Bank of America, Citigroup, and Wells Fargo.
Consolidation is being fueled by excess capital, a pro-consolidation regulatory agenda, and the pressure for banks to adopt AI and digital technologies.
The process evaluates targets based on strategic fit, actionability, and technological readiness rather than focusing primarily on financial scale and firepower.