{"id":163420,"date":"2024-05-20T06:17:08","date_gmt":"2024-05-20T06:17:08","guid":{"rendered":"https:\/\/securityaffairs.com\/?p=163420"},"modified":"2024-05-20T06:17:09","modified_gmt":"2024-05-20T06:17:09","slug":"grandoreiro-return-after-takedown","status":"publish","type":"post","link":"https:\/\/securityaffairs.com\/163420\/malware\/grandoreiro-return-after-takedown.html","title":{"rendered":"Grandoreiro Banking Trojan is back and targets banks worldwide<\/gwmw>"},"content":{"rendered":"
<\/div>\n

A new Grandoreiro banking trojan campaign has been ongoing since March 2024, following the disruption by law enforcement in January.<\/h2>\n\n\n\n

IBM X-Force warns of a new Grandoreiro<\/strong><\/a> banking trojan campaign that has been ongoing since March 2024. Operators behind the Grandoreiro banking trojan have resumed operations following a law enforcement takedown in January. <\/p>\n\n\n\n

The recent campaign is targeting over 1,500 banks in more than 60 countries across Central and South America, Africa, Europe, and the Indo-Pacific. The banking Trojan is likely operated as a Malware-as-a-Service (MaaS).<\/p>\n\n\n\n

Grandoreiro is a modular backdoor that supports the following capabilities:<\/gwmw><\/gwmw><\/p>\n\n\n\n