Grandoreiro is still active. Arrests in 2024 disrupted some operators, but did not remove the Windows banking-trojan family. Kaspersky’s analysis of 2024 samples found lighter regional builds, CAPTCHA and anti-sandbox checks, expanded analyst-tool detection, AES with Ciphertext Stealing (CTS) for string encryption, and mouse-activity recording apparently intended to confuse behavioral anti-fraud systems. WatchGuard then reported a Grandoreiro-associated campaign active through May 26, 2026 that used DLL side-loading against Portuguese banking targets.
The practical lesson for consumers and financial institutions is that Grandoreiro is not one “new version.” It is a shifting collection of related builds and campaigns that combine endpoint evasion with human-operated banking fraud.
What Grandoreiro is and why it matters
Grandoreiro is a Brazilian-origin Windows banking trojan active since at least 2016. It began with a strong Latin American focus and later expanded into Europe, Asia and Africa. Its purpose is to help criminals conduct fraudulent banking operations from a victim’s computer.
Depending on the build, capabilities include:
- Credential and browser-data theft.
- Keylogging and screen capture or sharing.
- Screen locking, fake banking windows and overlays.
- Remote operator control of the victim’s session.
- Theft of one-time passwords, transaction passwords and SMS-delivered tokens.
That combination matters because deleting a malicious file does not reverse exposed credentials, active sessions or transactions already approved by a bank.
#1 Best Overall
See the technical history in Kaspersky’s Grandoreiro analysis and the operational context in ESET’s disruption report.
What changed in the newer campaigns
The documented changes are a cluster of developments rather than a single universally confirmed release.
Fragmented, lighter and regional builds
After the 2024 law-enforcement action, Kaspersky observed the codebase splitting into lighter variants with fewer targets. One legacy-style branch focused mainly on Mexico and about 30 financial institutions, while other code continued in parallel. Smaller regional payloads can reduce the amount of code defenders see, limit unnecessary features and let separate operators maintain different branches. Older code may also remain useful when it is reliable and less familiar to detection teams.
Kaspersky describes the Mexico-focused branch in its light-variant announcement.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Mouse-activity recording
Newer 2024 samples recorded mouse activity, including average mouse speed over a short interval. Kaspersky assessed that this was likely intended to help mimic natural interaction and deceive anti-fraud systems that use behavioral analytics or machine learning.
The public evidence supports recording and a possible replay or imitation purpose. It does not prove that every build automatically replays movement, defeats every behavioral-biometric system or uses generative artificial intelligence. Banks should therefore treat mouse behavior as one signal among many, not as a sole authentication factor.
AES with Ciphertext Stealing
Kaspersky found AES with Ciphertext Stealing (CTS) used to encrypt strings without conventional padding. Analysts must identify and reproduce this less common mode before they can easily extract configuration and command strings.
CTS raises the cost of static analysis; it does not make the malware invisible, provide unbreakable encryption or necessarily describe how command-and-control traffic is protected. It is also unrelated to ransomware-style encryption of a victim’s files.
CAPTCHA, anti-VM and analyst-tool checks
Some 2024 campaigns presented a CAPTCHA before executing the main payload. The loader also checked for analysis tools, virtual environments, debuggers, suspicious execution paths, usernames, hostnames and geolocation mismatches.
These checks can stop an automated sandbox from reaching the banking component or cause a sample to terminate when monitoring software is present. They are obstacles, not proof that a human analyst cannot investigate the malware. They can also create false negatives in automated detection pipelines.
DLL side-loading reported in 2026
WatchGuard reported a Grandoreiro-associated campaign using DLL side-loading through four different software products against banks in Portugal. In this technique, a malicious DLL is placed beside a legitimate executable that loads it. The trusted executable can make the launch appear less suspicious.
This is a campaign-level observation, not evidence that every Grandoreiro sample now uses side-loading or that the legitimate software vendor is malicious. Defenders should inspect the loaded DLL’s origin, signature, path and load order rather than trusting the parent executable alone.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteWatchGuard’s current research index is available at WatchGuard research.
How a Grandoreiro infection reaches a victim
The exact files and brands change, but the high-level flow is usually:
- Lure: A phishing message, fake tax or invoice notice, phone-bill theme or malvertising campaign creates urgency.
- Redirect or download: The victim is sent to a malicious site or asked to open a ZIP archive or installer.
- Loader execution: The archive may contain a legitimate executable beside a malicious loader, or another installer format.
- Environment checks: The loader evaluates location, host details, analysis tools, sandbox indicators and other conditions.
- Payload retrieval: The banking component is downloaded only when the environment appears suitable.
- Persistence and control: The malware establishes access and contacts operator infrastructure.
- Fraud: A human operator may control the session, display overlays, capture credentials or one-time codes and initiate transactions.
Do not assume that a sandbox that saw only the loader proved the endpoint was clean. The main payload may have been withheld because the environment failed the checks.
Who is prepared to be targeted?
Kaspersky reported that 2024 configurations listed approximately 1,700 financial institutions and 276 cryptocurrency wallets across 45 countries and territories. Those figures describe prepared target lists, not 1,700 confirmed breaches or a count of successful victims. A bank appearing in a decrypted configuration means the malware could act if a suitable local operator or money mule were available.
Country and institution lists can change between builds, and Kaspersky’s figures are analysis and telemetry estimates rather than a census of all infections. Its 2024 financial-malware report attributed 17.1% of notable banking-trojan detections to Grandoreiro, a Kaspersky-specific metric and denominator: Financial Threat Report 2024.
Why the evasion techniques are complementary
| Attacker problem | Observed response | Defensive implication |
|---|---|---|
| Static strings reveal functions and infrastructure | Encrypted strings, including AES-CTS | Look for unpacking and runtime behavior, not only readable indicators. |
| Automated sandboxes execute payloads immediately | CAPTCHA and environment checks | Use interactive analysis and compare execution in alternate environments. |
| Analysts inspect processes and traffic | Virtual-machine, debugger and analyst-tool detection | Harden analysis systems and investigate divergent execution paths. |
| Behavioral systems recognize automation | Mouse-activity recording and possible imitation | Combine device, identity, transaction and behavioral signals. |
| Operators and domains are removed | Fragmented branches and replacement infrastructure | Track family relationships, not only individual domains or hashes. |
| Trusted software appears in the process chain | DLL side-loading | Validate DLL path, signature, parent-child relationship and load order. |
These tactics address different layers. CTS and anti-debugging frustrate malware analysis; mouse recording targets bank-side fraud analytics; fragmentation improves the criminals’ operational resilience.
Did the 2024 arrests stop Grandoreiro?
No. The February 2024 operation and arrests removed some people and infrastructure, but they did not remove the family’s code, every affiliate or every developer. Kaspersky reported continuing campaigns, new infrastructure and lighter branches after the action. WatchGuard’s May 26, 2026 report is further evidence of associated activity.
These outcomes are different:
- Arresting known operators.
- Seizing command infrastructure.
- Blocking domains.
- Removing an executable from an endpoint.
- Preventing source code, tools or relationships from being reused.
A takedown can reduce activity while leaving enough code, access or personnel for another branch to continue.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Best Value
Defensive priorities for organizations
Endpoint telemetry
- Alert when Office, browsers, archive tools, script hosts or installers spawn unusual executables.
- Investigate unsigned DLLs loaded from user-writable, temporary, download or profile directories.
- Hunt for side-loading, malicious VBS, MSI, ZIP and shortcut-based delivery.
- Record processes that enumerate analysis tools or terminate when monitoring is present.
- Monitor unexpected screen-locking, overlays and credential access around banking sessions.
Network telemetry
- Monitor newly registered or low-reputation domains and repeated DNS requests consistent with domain-generation algorithms.
- Investigate encrypted outbound connections immediately following archive, MSI, VBS or DLL-loading activity.
- Flag regional inconsistencies and workstation traffic to cloud VPS infrastructure without a business reason.
Kaspersky described three DGAs for command-and-control communications and provides indicators in its technical analysis.
Identity and banking controls
- Use hardware-backed MFA where available.
- Prefer transaction signing and out-of-band confirmation for high-risk payments over approval-only push prompts.
- Score device and session risk, and monitor transaction velocity and beneficiary changes.
- Use separate, hardened workstations for financial operations.
- Maintain a rapid bank-contact and account-freeze procedure.
Microsoft’s general guidance includes cloud-delivered protection, Defender for Endpoint in block mode and relevant attack-surface-reduction rules. These are broad hardening measures, not proof of Grandoreiro-specific coverage: Microsoft Security Blog.
What individuals should do after suspected infection
- Disconnect the computer from the network, but preserve evidence rather than immediately destroying it.
- Do not access banking or cryptocurrency accounts from the suspected device.
- From a known-clean device, contact each bank or payment provider.
- Ask for review or blocking of recent transactions, new beneficiaries and online-banking sessions.
- Change email, financial and other important passwords from the clean device.
- Revoke active sessions and reset MFA methods if compromise is possible.
- Preserve suspicious messages, archives, filenames, timestamps and security alerts.
- Run an enterprise-quality scan or reimage the machine when compromise cannot be confidently removed.
- Review browser password stores, saved payment details, email-forwarding rules and remote-access software.
- Report fraud to the financial institution and the appropriate law-enforcement or national cybercrime channel.
A single antivirus scan cannot guarantee that stolen credentials, active sessions or fraudulent transactions are resolved.
What remains uncertain
- Whether the 2026 side-loading campaign shares all code or operators with the 2024 samples.
- Whether mouse data is automatically replayed in every build.
- Which operators control each regional branch.
- The number of successful victims and total losses in the latest campaigns.
- Whether every institution in a target list was actively attacked.
Those limits are important: prepared targets, detected users, attempted fraud, successful fraud and confirmed losses are separate measurements.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11The Bottom Line
Grandoreiro survived the 2024 arrests by evolving as a family of regional and operational branches. Treat CAPTCHA and anti-analysis checks as reasons to improve telemetry—not as invisibility—and combine endpoint, identity, network and bank-side fraud controls. For anyone who may have been infected, protecting accounts from a clean device and contacting the bank quickly matters as much as removing the malware.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




