
Grandoreiro Banking Trojan Resurfaces Targeting Mexico with New DLL Sideloading Campaign
CybersecurityMalwareFinancialFraudHacking
The Grandoreiro banking trojan has resurfaced following its disruption in early 2024, now targeting Mexico with a new DLL sideloading campaign. Mexico accounts for 40% of recent detections, indicating a focused regional shift. The malware employs DLL sideloading techniques to execute malicious payloads while evading detection. No specific CVE IDs, technical indicators, or exact dates for the resurgence were provided in the report. The campaign primarily impacts financial institutions and users in Mexico through phishing and malware distribution. Grandoreiro’s operators remain active despite prior law enforcement actions.