Malware

Grandoreiro banking malware targets Spanish manufacturers

0

A new Grandoreiro banking malware campaign is targeting organizations in the Spanish-speaking nations of Mexico and Spain.

According to Zscaler ThreatLabz researchers, in this campaign, the threat actors impersonate government officials from the Attorney General’s Office of Mexico City and from the Public Ministry in the form of spear-phishing emails in order to lure victims to download and execute ‘Grandoreiro.’

The ongoing attacks, which started in June 2022, were found targeting automotive, civil and industrial construction, logistics, and machinery sectors via multiple infection chains in Mexico and chemicals manufacturing industries in Spain.

The infection chain begins with a spear-phishing message written in Spanish that includes a link that points to a website which further downloads a malicious ZIP archive on the victim’s machine.

The phishing messages incorporate themes such as payment refunds, litigation notifications, cancellation of mortgage loans, and deposit vouchers, to activate the infections.

The ZIP archive contains the Grandoreiro Loader module with a PDF Icon that lures the victim into opening it. Once the file is opened, it downloads and executes the “Grandoreiro” payload (400MB) from a Remote HFS server which further communicates with the C2 server using traffic identical to LatentBot.

The loader is designed to gather system information, retrieve a list of installed antivirus solutions, cryptocurrency wallets, banking, and mail apps, and exfiltrate the information to a remote server.

Grandoreiro is a prolific banking trojan that has been active since at least 2016 and includes several functionalities such as record keystrokes, execute arbitrary commands, mimic mouse and keyboard movements, restrict access to specific websites, auto-update itself, and establish persistence via a Windows Registry change.

It is reported that Grandoreiro is continuously evolving into a sophisticated malware posing significant threats to employees and their organizations.

Image Credits : Bleeping Computers

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Estonia blocked cyberattacks claimed by Killnet group

Previous article

Hackers target Bitcoin ATMs by exploiting zero-day bug

Next article

You may also like

More in Malware

Comments

Leave a reply

Your email address will not be published. Required fields are marked *