2026-08-20NOTABLEThe evasion logic is backwards on purpose: a clean, well-stocked desktop is what makes this malware quit
Grandoreiro
malware · malware:grandoreiro single-source
Latin American banking trojan family, targeted at financial institutions and their customers, partially disrupted by a January 2024 law-enforcement operation and still active. Acronis documented an August 2026 wave delivered by sideloading a malicious library through a renamed copy of a legitimate file-management utility, gated behind an inverted sandbox check. Distinct from the separately tracked 2026 Iberian campaign record; no cited source links the two waves.
Coverage
2
1 about it · 1 mention · first 2026-05-29 → last 2026-08-20
Latest activity
2026-08-20
The evasion logic is backwards on purpose: a clean, well-stocked desktop is what makes this malware quit
Peak priority
notable
1 notable
Targets
finance
sectors: finance · regions: latam, europe
Sources cited
4
4 hosts
Defender insights
What each entry about Grandoreiro tells a defender to do, newest first.
Triage
Story timeline
Every entry that names Grandoreiro, newest first. Rows tagged mention only name it in passing: they are listed for completeness and add nothing to the action items, pivots or ATT&CK profile on this page.
- 2026-08-20Grandoreiro's loader decides it is in a sandbox when it finds seven ordinary desktop shortcuts, an inverted environment check, behind a two-hop DLL sideload
- 2026-05-29WatchGuard documents Grandoreiro's Delphi-DLL-side-loading + WebSocket/STUN C2 against Portuguese & Spanish banks; ESET maps parallel Android BTMOB MaaS
Hunting pivots
ATT&CK techniques (10 across 4 tactics)
10 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- ExecutionHijack Execution Flow: DLL
- StealthMasquerading: Match Legitimate Resource Name or Location · Deobfuscate/Decode Files or Information · Virtualization/Sandbox Evasion: System Checks · Hide Artifacts: Hidden Window · Hijack Execution Flow: DLL
- DiscoverySystem Network Configuration Discovery · Process Discovery · System Information Discovery · Virtualization/Sandbox Evasion: System Checks · System Location Discovery
- Command and ControlApplication Layer Protocol: Web Protocols
Execution TA0002
T1574.001Hijack Execution Flow: DLL×1
Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.
Evidence: 2026-08-20/grandoreiro-dll-sideload-inverted-sandbox-check · ATT&CK page ↗
Stealth TA0005
T1036.005Masquerading: Match Legitimate Resource Name or Location×1
Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation.
Evidence: 2026-08-20/grandoreiro-dll-sideload-inverted-sandbox-check · ATT&CK page ↗
T1140Deobfuscate/Decode Files or Information×1
Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis. They may require separate mechanisms to decode or deobfuscate that information depending on how they intend to use it. Methods for doing that include built-in functionality of malware or by using utilities present on the system.
Evidence: 2026-08-20/grandoreiro-dll-sideload-inverted-sandbox-check · ATT&CK page ↗
T1497.001Virtualization/Sandbox Evasion: System Checks×1
Adversaries may employ various system checks to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. Adversaries may use the information learned from Virtualization/Sandbox Evasion during automated discovery to shape follow-on behaviors.
Evidence: 2026-08-20/grandoreiro-dll-sideload-inverted-sandbox-check · ATT&CK page ↗
T1564.003Hide Artifacts: Hidden Window×1
Adversaries may use hidden windows to conceal malicious activity from the plain sight of users. In some cases, windows that would typically be displayed when an application carries out an operation can be hidden. This may be utilized by system administrators to avoid disrupting user work environments when carrying out administrative tasks.
Evidence: 2026-08-20/grandoreiro-dll-sideload-inverted-sandbox-check · ATT&CK page ↗
T1574.001Hijack Execution Flow: DLL×1
Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.
Evidence: 2026-08-20/grandoreiro-dll-sideload-inverted-sandbox-check · ATT&CK page ↗
Discovery TA0007
T1016System Network Configuration Discovery×1
Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems. Several operating system administration utilities exist that can be used to gather this information. Examples include Arp, ipconfig/ifconfig, nbtstat, and route.
Evidence: 2026-08-20/grandoreiro-dll-sideload-inverted-sandbox-check · ATT&CK page ↗
T1057Process Discovery×1
Adversaries may attempt to get information about running processes on a system. Information obtained could be used to gain an understanding of common software/applications running on systems within the network. Administrator or otherwise elevated access may provide better process details. Adversaries may use the information from Process Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
Evidence: 2026-08-20/grandoreiro-dll-sideload-inverted-sandbox-check · ATT&CK page ↗
T1082System Information Discovery×1
An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use this information to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. This behavior is distinct from Local Storage Discovery which is an adversary's discovery of local drive, disks and/or volumes.
Evidence: 2026-08-20/grandoreiro-dll-sideload-inverted-sandbox-check · ATT&CK page ↗
T1497.001Virtualization/Sandbox Evasion: System Checks×1
Adversaries may employ various system checks to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. Adversaries may use the information learned from Virtualization/Sandbox Evasion during automated discovery to shape follow-on behaviors.
Evidence: 2026-08-20/grandoreiro-dll-sideload-inverted-sandbox-check · ATT&CK page ↗
T1614System Location Discovery×1
Adversaries may gather information in an attempt to calculate the geographical location of a victim host. Adversaries may use the information from System Location Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
Evidence: 2026-08-20/grandoreiro-dll-sideload-inverted-sandbox-check · ATT&CK page ↗
Command and Control TA0011
T1071.001Application Layer Protocol: Web Protocols×1
Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.
Evidence: 2026-08-20/grandoreiro-dll-sideload-inverted-sandbox-check · ATT&CK page ↗
Entries about Grandoreiro (1)
Where this entity is cited
Source distribution
- acronis.com1 (25%)
- thehackernews.com1 (25%)
- watchguard.com1 (25%)
- welivesecurity.com1 (25%)
All cited sources (4)
- acronis.comAcronis Threat Research Unithttps://www.acronis.com/en/tru/posts/grandoreiro-goes-north-from-brazil-to-mexico-with-a-new-dll-sideloading-campaign/
- thehackernews.comThe Hacker Newshttps://thehackernews.com/2026/05/grandoreiro-malware-and-btmob-rat.html
- watchguard.comWatchGuard Secplicityhttps://www.watchguard.com/wgrd-security-hub/secplicity-blog/grandoreiro-malware-campaign-targets-europe-and-latin-america
- welivesecurity.comESET WeLiveSecurity, BTMOBhttps://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/