# Grandoreiro Banking Trojan Resurfaces in Mexico Campaign

**Published:** 2026-08-20T18:29:06.622Z  
**Topic:** Banking  
**Sentiment:** neutral  
**Publisher:** TrendWatcher — https://www.trendwatcher.in/article/7a3a9509-8a88-45b5-aa61-6d6d770548b1

The Grandoreiro banking trojan has resurfaced with a new campaign targeting Mexico, which accounts for 40% of recent detections despite 2024 law enforcement.

Mexico currently accounts for 40% of all detected Grandoreiro banking trojan activity, marking a significant resurgence for the malware despite a major international law enforcement disruption in January 2024 [1]. The campaign, which relies on sophisticated DLL sideloading to bypass security, poses a persistent threat to financial institutions and their customers across Latin America and beyond [3].

| At a glance | |
|---|---|
| Mexico Detection Share | 40% of total activity |
| Primary Target Regions | Latin America, Spain, Europe |
| Malware Origin | Brazil (circa 2016) |
| Known Bank Targets | Over 1,500 institutions |

## Evolving Tactics and Distribution
The latest campaign, observed by researchers in May 2026, utilizes a legitimate file-management tool, Duplicate Files Finder, to execute malicious code [1]. By renaming the application and placing a malicious library alongside it, attackers successfully employ DLL sideloading to trigger the trojan while appearing as a trusted process [3]. This method is paired with extensive anti-analysis features, including checks for virtualization, sandbox environments, and nearly 50 distinct security or monitoring tools, which the malware scans for before establishing contact with its command-and-control infrastructure [1].

While the malware's overall activity remains below its historical peak, the current campaign demonstrates a shift toward more stealthy, modular deployment [1]. Researchers note that the operators have moved away from simple distribution, instead using invoice-themed ZIP files to trick users into installing the payload [3]. This strategy follows a broader trend of "malware-as-a-service" operations, which have allowed the trojan to persist by fragmenting its codebase into smaller, more difficult-to-detect versions [3].

## Global Reach and Financial Impact
Although the malware originated in Brazil and remains heavily concentrated in Spanish-speaking regions, its reach has expanded significantly since its 2016 inception [3]. Recent telemetry shows that while Mexico leads with 40% of detections, Spain follows at 17%, Peru at 13%, and Argentina at 10% [1]. The trojan is designed to steal banking credentials through keystroke logging, screen sharing, and remote device control, targeting more than 1,500 banks across over 60 countries [2].

The persistence of the threat suggests that the 2024 law enforcement operation, which resulted in the arrest of five administrators, did not fully dismantle the underlying infrastructure [3]. Instead, the operators have adapted by impersonating various government entities, including tax and finance authorities in Mexico, Argentina, and South Africa, to increase the effectiveness of their phishing campaigns [2].

## What to watch
*   **Geographic Spread:** Monitor whether detection clusters expand beyond the current focus on Latin America and Spain into other regions, as seen in recent South African campaigns [2].
*   **Infrastructure Evolution:** Watch for further updates to the "light" version of the malware, which researchers suggest is being used to maintain operations despite ongoing international takedown efforts [4].
*   **Delivery Vectors:** Observe if attackers move beyond invoice-themed spam to new social engineering tactics as security providers update their detection signatures for the current DLL sideloading chain [3].

The ability of the Grandoreiro operation to reorganize after high-profile arrests highlights the resilience of modern, decentralized cybercrime networks. Whether this latest campaign represents a permanent shift in strategy or a temporary surge remains an open question for financial security teams.

## Sources
1. Infosecurity Magazine — [Grandoreiro Resurfaces in Mexico With New DLL Sideloading Campaign](https://www.infosecurity-magazine.com/news/grandoreiro-mexico-dll-sideloading/)
2. Blog — [Newly Updated Grandoreiro Banking Trojan Distributed Via Phishing...](https://blog.knowbe4.com/grandoreiro-banking-trojan-distributed-via-phishing-campaigns)
3. Dark Reading — ['Grandoreiro' Malware Resurfaces With Mexico Campaign](https://www.darkreading.com/cyberattacks-data-breaches/grandoreiro-resurfaces-mexico-campaign)
4. Vsdaily — [Grandoreiro Banking Trojan Resurfaces with New ‘Light’ Version...](https://vsdaily.com/grandoreiro-banking-trojan-resurfaces-with-new-light-version-expands-global-reach-and-targets-mexico/)

---
Cite as: TrendWatcher, "Grandoreiro Banking Trojan Resurfaces in Mexico Campaign", https://www.trendwatcher.in/article/7a3a9509-8a88-45b5-aa61-6d6d770548b1
