Malware

Police disrupt Grandoreiro banking malware operation

0

The Federal Police of Brazil and cybersecurity researchers have disrupted the Grandoreiro banking malware operation, leading to the arrest of individuals controlling the malware’s infrastructure.

Operation Grandoreiro was supported by ESET, Interpol, the National Police in Spain, and Caixa Bank.

Brazil’s federal police announced five arrests and thirteen search and seizure actions in Sao Paulo, Santa Catarina, Para, Goias, and Mato Grosso.

The malware operation responsible for electronic banking fraud, using banking malware has been targeting Spanish-speaking countries since 2017.

The criminal structure is suspected of moving at least 3.6 million euros through fraud.

According to Caixa Bank’s records, the malware operators are linked to fraud that has caused roughly $120,000,000 in losses.

Grandoreiro is a Windows banking trojan first documented by ESET in 2020, which has been one of the primary threats to Spanish speakers since the beginning of its operation in 2017.

The banking trojan has capabilities to both steal data through keyloggers and screenshots as well as siphon bank login information from overlays when an infected victim visits pre-determined banking sites targeted by the threat actors. It can also display fake pop-up windows and block the victim’s screen.

Grandoreiro developers released frequent updates to add new features and enhance the malware’s capabilities.

ESET could trace Grandoreiro’s servers despite the malware’s use of a Domain Generation Algorithm (DGA) through a combination of tracking and analysis techniques.

The researchers analyzed the DGA mechanism, which generates a new domain every day, and found that it uses the current date and hardcoded configuration, allowing them to predict future domains.

ESET has extracted a total of 105 different dga_ids from the Grandoreiro samples known to them. 79 of these configurations at least once generated a domain that resolved to an active C&C server IP address during the course of tracking.

Most of the victims are in Spain, Mexico, and Brazil, while the most impacted operating system is Windows 10, followed by 7, 8, and 11.

At this time, it is unclear if the arrested individuals held a leading role in the operation or if there’s a risk of Grandoreiro returning in the future using new infrastructure.

However, the latest disruption has brought the malware operations to a complete halt for now.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

A mishandled GitHub token exposed Mercedes-Benz source code

Previous article

Data of 750 M Indian Mobile subscribers sold on hacker forums

Next article

You may also like

More in Malware

Comments

Leave a reply

Your email address will not be published. Required fields are marked *